Developer program
Roles and permissions
Control who can connect projects, run scans, triage findings and administer policy.
The console has role-aware navigation for Developer, Security Analyst, DevOps Engineer, Admin, Test and Org Admin. The exact access assigned by an organization remains authoritative.
- Developers, analysts and DevOps users receive the project capabilities their organization enables.
- Org Admins can view organization-wide developer analytics and member data.
- Test-only DAST and test-performance surfaces are limited to eligible roles.
- Administrative user and model controls are restricted to administrators.
Effective access also depends on the source provider. A Cortex role does not grant access to a GitHub, GitLab, Bitbucket or Azure repository the identity cannot access.
Use least privilege, review memberships periodically, and preserve the acting identity for scans, finding decisions, policy changes and exports.

