Overview
Remediation projects help your teams organize, execute on, track and report on remediation efforts with up-to-date asset and instance-level granularity. However, given the sensitive nature of this data, it is important that projects are restricted to only those with appropriate role-based access.
This article provides a concise reference for access to remediation projects and project-specific actions within Balbix. Permission levels are structured to vary by user role and by the user’s relationship to a specific project. Note that user role-based access permissions can be viewed under ‘Company Settings > Roles and access control’.
Project-Related Role-Based Access Control
Create a Project
Users typically create remediation projects by selecting the exposures in scope within one of the core Exposure Management Tables: Asset Vulnerabilities or AppSec Findings and selecting “Create Project”
Access Control Permissions Required:
‘Create Projects/Ticket’, and
‘Exposure Management > Asset Vulnerabilities: Full’, or ‘Exposure Management > AppSec Findings: Full’, depending on the type of associated exposures.
Working with Projects
Once projects are created, users can view and share related information by navigating to the projects table at Exposure Management > Remediation & Mitigations from the left navigation. Here, users can view project details, email a project report, subscribe a team to automated/ongoing project reports, or export remediation details.
Access Control Permissions Required:
‘Exposure Management > Remediation And Mitigations access: Full’: provides access to all projects within the environment.
‘Exposure Management > Remediation And Mitigations access: View’: provides access only to projects where the user is listed as Creator, Owner or Team Member.
Editing Projects
After creation, projects can be edited to make changes to basic project information, such as name, description, due date, owner or associated team members.
Access Control Permissions Required:
The same permissions required for project creation above: ‘Create Projects/Ticket’, and ‘Exposure Management > Asset Vulnerabilities: Full’ or ‘Exposure Management > AppSec Findings: Full’
Exposure Management > Remediation And Mitigations access: "Full": provides edit access to all projects.
Exposure Management > Remediation And Mitigations access: "View": provides edit access only to projects where the user is listed as Creator, Owner or Team Member.
Deleting Projects
Users with appropriate permissions can also choose to delete remediation projects. On deletion, all data related to the project is removed and project tracking stops.
Access Control Permissions Required:
‘Exposure Management > Remediation And Mitigations access: Full’: provides access only to projects where the user is listed as Creator, Owner or Team Member. If the user has a role of ‘Admin’ or ‘Balbix CS User’, then the scope is all projects.
‘Exposure Management > Remediation And Mitigations access: View’: provides access only to projects where the user is listed as Creator, Owner or Team Member.
Project Permissions Summary Table
See below for a table summarizing the project-specific actions available to users with specified permissions. Here, ‘Project Table Access’ refers to the permission level configured for the user within ‘Company Settings > Roles and access control > Exposure Management > Remediation And Mitigations’.
Action | Project Table Access: Full | Project Table Access: View | Project Table Access: None |
Create Project | ✅ Requires Create Project permissions | ✅ Requires Create Project permissions | Requires Create Project permissions |
View List of Projects | ✅ All projects | ✅ Accessible projects only | ❌ |
View Project Details | ✅ All projects | ✅ Accessible projects only | ❌ |
Email Project Report | ✅ All projects | ✅ Accessible projects only | ❌ |
Manage Project Email Subscriptions | ✅ All projects | ✅ Accessible projects only | ❌ |
Export Project | ✅ All projects | ✅ Accessible projects only | ❌ |
Edit Project | ✅ All projects, requires Create Project permissions | ✅ Accessible projects only, requires Create Project permissions | ❌ |
Delete Project | ✅ Accessible projects only; all projects if Admin or Balbix CS User role | ✅ Accessible projects only | ❌ |
Accessible Projects: Projects where listed as Creator, Owner or Team Member
Create Project permissions: ‘Create Projects/Ticket’, and ‘Exposure Management > Asset Vulnerabilities: Full’, or ‘Exposure Management > AppSec Findings: Full’, depending on the type of associated exposures.