Documentation Index

Fetch the complete documentation index at: https://docs.safe.security/llms.txt

Use this file to discover all available pages before exploring further.

Project Permissions Reference

Prev Next

Overview

Remediation projects help your teams organize, execute on, track and report on remediation efforts with up-to-date asset and instance-level granularity. However, given the sensitive nature of this data, it is important that projects are restricted to only those with appropriate role-based access.

This article provides a concise reference for access to remediation projects and project-specific actions within Balbix. Permission levels are structured to vary by user role and by the user’s relationship to a specific project. Note that user role-based access permissions can be viewed under ‘Company Settings > Roles and access control’.

Project-Related Role-Based Access Control

Create a Project

Users typically create remediation projects by selecting the exposures in scope within one of the core Exposure Management Tables: Asset Vulnerabilities or AppSec Findings and selecting “Create Project”

Access Control Permissions Required:

  • ‘Create Projects/Ticket’, and

  • ‘Exposure Management > Asset Vulnerabilities: Full’, or ‘Exposure Management > AppSec Findings: Full’, depending on the type of associated exposures.

Working with Projects

Once projects are created, users can view and share related information by navigating to the projects table at Exposure Management > Remediation & Mitigations from the left navigation. Here, users can view project details, email a project report, subscribe a team to automated/ongoing project reports, or export remediation details.

Access Control Permissions Required:

  • ‘Exposure Management > Remediation And Mitigations access: Full’: provides access to all projects within the environment.

  • ‘Exposure Management > Remediation And Mitigations access: View’: provides access only to projects where the user is listed as Creator, Owner or Team Member.

Editing Projects

After creation, projects can be edited to make changes to basic project information, such as name, description, due date, owner or associated team members.

Access Control Permissions Required:

  • The same permissions required for project creation above: ‘Create Projects/Ticket’, and ‘Exposure Management > Asset Vulnerabilities: Full’ or ‘Exposure Management > AppSec Findings: Full’

  • Exposure Management > Remediation And Mitigations access: "Full": provides edit access to all projects.

  • Exposure Management > Remediation And Mitigations access: "View": provides edit access only to projects where the user is listed as Creator, Owner or Team Member.

Deleting Projects

Users with appropriate permissions can also choose to delete remediation projects. On deletion, all data related to the project is removed and project tracking stops.

Access Control Permissions Required:

  • ‘Exposure Management > Remediation And Mitigations access: Full’: provides access only to projects where the user is listed as Creator, Owner or Team Member. If the user has a role of ‘Admin’ or ‘Balbix CS User’, then the scope is all projects.

  • ‘Exposure Management > Remediation And Mitigations access: View’: provides access only to projects where the user is listed as Creator, Owner or Team Member.

Project Permissions Summary Table

See below for a table summarizing the project-specific actions available to users with specified permissions. Here, ‘Project Table Access’ refers to the permission level configured for the user within ‘Company Settings > Roles and access control > Exposure Management > Remediation And Mitigations’.

Action

Project Table Access: Full

Project Table Access: View

Project Table Access: None

Create Project

✅   Requires Create Project permissions

✅   Requires Create Project permissions

Requires Create Project permissions

View List of Projects

✅ All projects

✅ Accessible projects only

View Project Details

✅ All projects

✅ Accessible projects only

Email Project Report

✅ All projects

✅ Accessible projects only

Manage Project Email Subscriptions

✅ All projects

✅ Accessible projects only

Export Project

✅ All projects

✅ Accessible projects only

Edit Project

✅ All projects, requires Create Project permissions

✅ Accessible projects only, requires Create Project permissions

Delete Project

✅ Accessible projects only; all projects if Admin or Balbix CS User role

✅ Accessible projects only

  • Accessible Projects: Projects where listed as Creator, Owner or Team Member

  • Create Project permissions: ‘Create Projects/Ticket’, and ‘Exposure Management > Asset Vulnerabilities: Full’, or ‘Exposure Management > AppSec Findings: Full’, depending on the type of associated exposures.