Skip to main content

RBAC

Role-based access control (RBAC) ensures that the right people can see, triage, and manage vulnerabilities without overexposing sensitive data or configuration.

Use this guide to review key RBAC considerations for Vulnerability Management.

Typical Roles

Examples of roles and responsibilities:

  • Security Operations (SecOps)
    • Full visibility across all vulnerabilities and assets.
    • Configure risk models, SLAs, and exception policies.
    • Create Initiatives and Remediation Tasks.
  • Application/Service Owners
    • See vulnerabilities for their applications and dependent infrastructure.
    • Own remediation tasks and tickets.
    • Request exceptions and provide justifications.
  • Platform/Infrastructure Teams
    • Focus on vulnerabilities on shared platforms (e.g., Kubernetes, databases, networks).
    • Collaborate with app teams on remediation plans.
  • Auditors/Compliance
    • Read‑only access to dashboards, reports, and evidence.
    • No ability to change configuration or exceptions.

Permissions and Scoping

Guidelines:

  • Scope access by OU, application, or environment where appropriate.
  • Limit who can:
    • Edit risk models and SLAs.
    • Create or approve exceptions.
    • Change ownership mappings.
  • Provide read‑only roles for broad visibility, write access only where necessary.

RBAC should align with your wider Cloudaware and CMDB permission model so that users see consistent views across modules.