Skip to content

Latest commit

 

History

History
109 lines (63 loc) · 7.11 KB

File metadata and controls

109 lines (63 loc) · 7.11 KB

Auditor role template

This is a Group-level read-only role, meaning an Auditor can only view certain areas and functions in Snyk and cannot create PRs, Projects, and more.

This role can view issues, results of scans, and reports. An Auditor often verifies that there is a scan snapshot for a particular resource or Snyk Project. The Auditor may be external to the company.

Group-level permissions

To create this role, enable the following permissions in the relevant categories:

Group Management

PermissionEnabled?
View Groupstrue
Edit Group detailsfalse
View Group settingsfalse
Edit settingsfalse
View Group notification settingsfalse
Edit Group notification settingsfalse

Organization management

PermissionEnabled?
View Organizationstrue
Edit Organizationsfalse
Remove Organizationsfalse

AppRisk management

PermissionEnabled?
View AppRisktrue
Edit AppRiskfalse

Audit Log management

PermissionEnabled?
View Audit Logstrue

Insights management

PermissionEnabled?
Access Insightstrue

Reports management

PermissionEnabled?
View reportstrue

Security and License Policies

PermissionEnabled?
View Policiestrue
Create Policiesfalse
Edit Policiesfalse
Delete Policiesfalse

User management

PermissionEnabled?
View userstrue
Invite usersfalse
Manage usersfalse
Add usersfalse
Provision usersfalse
User Leavefalse
User Removefalse

The remaining categories of permissions listed below should have all permissions within them set to disabled:

  • IaC settings management
  • Issue management
  • Request access management
  • Role management
  • Service account management
  • Snyk Apps management
  • Snyk Preview management
  • SSO settings management
  • Tags management

Organization-level permissions

To create this role, enable the following permissions in the relevant categories:

Organization management

PermissionEnabled?
View Organizationtrue
Edit Organizationfalse
Remove Organizationfalse

Audit Log management

PermissionEnabled?
View audit logstrue

Collection management

PermissionEnabled?
View Collectionstrue
Create Collectionfalse
Edit Collectionsfalse
Delete Collectionsfalse

Container Image management

PermissionEnabled?
View container imagetrue
Create container imagefalse
Edit container imagefalse

Integration management

PermissionEnabled?
View integrationstrue
Edit integrationsfalse

Project management

PermissionEnabled?
View Projecttrue
Add Projectfalse
Edit Projectfalse
Edit Project statusfalse
Test Projectfalse
Move Projectfalse
Remove Projectfalse
View Project historytrue
Edit Project integrationsfalse
Edit Project attributesfalse
View Jira issuestrue
Create Jira issuesfalse
Edit Project Tagsfalse

Project Ignore management

PermissionEnabled?
View Project Ignorestrue
Create Project Ignoresfalse
Edit Project Ignoresfalse
Remove Project Ignoresfalse

Reports management

PermissionEnabled?
View Organization reportstrue

Snyk Cloud management

PermissionEnabled?
View environmentsfalse
Create environmentsfalse
Delete environmentsfalse
Update environmentsfalse
View scanstrue
Create scansfalse
View resourcestrue
View artifactstrue
Create artifactsfalse
View Custom Rulesfalse
Create Custom Rulesfalse
Edit Custom Rulesfalse
Delete Custom Rulesfalse

Webhook management

PermissionEnabled?
View Outbound Webhookstrue
Create Outbound Webhooksfalse
Remove Outbound Webhooksfalse

The remaining categories of permissions listed below should have all permissions within them set to disabled:

  • Billing management
  • Entitlement management
  • Kubernetes Integration management
  • Package management
  • Project pull request management
  • Service account management
  • Snyk Apps management
  • Snyk Preview management
  • User management