Users, Groups, Roles, and Access

Coverity on Polaris

Version
latest
In Coverity on Polaris, users correspond to people. Users can be placed in groups for the purpose of easily managing project access.

The following figure shows an example:


Coverity on Polaris user hierarchy
  • Your organization contains users and groups.
  • A group contains users and other groups.
  • A user can belong to more than one group.

Users and groups can either be managed within Coverity on Polaris itself, or you can choose to integrate a SAML 2.0 Identity Provider (IDP).

Managing users and groups within Coverity on Polaris means that all your decisions about access to testing results are logically contained in one place.

If you choose SAML integration, you get the convenience of managing users and groups in one place and having Coverity on Polaris automatically use the same information.
Note: Black Duck also strongly recommends setting up an IP allow list for increased security. For more information, see Security.

Roles

Overview

There are two levels of roles assigned in different ways and govern separate aspects of Coverity on Polaris:

  • The Organization Role is assigned once and governs what areas of the site the user has access to outside of Projects.
  • The Project Role is assigned per Project and governs what a user can do within that Project.

The Projects that a user can view/access can be determined by either the Organizational Role or the Project membership:

  • If the user has an Org Role of Org Admin or Application Manager, they automatically have access and administrative privileges to all Projects in the organization.
  • If the user has an Org Role of Contributor or Observer, they will only have access to Projects for which they are a member of (where they can hold the role of Administrator (Project), Contributor or Observer).

Organizational Roles

These are assigned when the Organizational Administrator adds a user or creates a group. They can also be changed by the Organizational Administrator.
Table 1. Organizational Roles
User Role Access * Definition Notes
Administrator (Organization) Global Manages all of Coverity on Polaris including adding new users, creating groups, SAML integration and service account settings.
  • At least one user has this role.
  • An organization owner is automatically assigned the same privileges as an organization administrator, and these cannot be changed while a person is still an owner. To assign a different role, remove owner status and then assign the new role.
  • This is the only role that has access to the My Organization section. It is the only role that can add new users to Coverity on Polaris.
  • Can create new projects and applications.
Application Manager Global Manages all projects and applications.
  • Can add existing users/groups to projects and applications.
  • Can create new projects and applications.
Contributor Via Membership to Project/Application Can be assigned as an individual member or group to an application or project role.
  • Can create new projects and applications (with projects they have a Project Admin role).
  • Only have Project Admin role with projects or applications they are assigned or created.

  • Can be assigned any of the Project Roles below.
Observer Via Membership to Project/Application Can be assigned as an individual member or group to an application or project role.
  • Cannot create projects or applications.
  • Can view assigned projects and applications.

  • Can be assigned any of the Project Roles below.

*Global - Has access to and can manage all projects and applications. Organizational Administrators can add new users/groups and has access to the “My Organization” section.

Via Membership to Project / Application - Has access to assigned projects and/or applications. Users can only view applications that include projects they have been assigned a role for.

  • Applications allow members to view summary data and run reports from multiple projects. Members must have a project role to view more detailed individual project information.
  • For applications, these roles can view applications that include assigned projects or that they are assigned membership to.

Project Roles (Members)

These are assigned to the individual user or group per project or application. These can be assigned by Organizational Administrator, Application Manager or Project Administrator. See Add and Remove Members for a Project.

Table 2. Project Roles (Members)
Project / Application Role Definition Notes
Administrator (Project)
  • Can create applications with projects they have Project Admin role for (if also assigned Organizational Contributor role).
  • Manages user and group access to a project and can make changes to the project.
  • Automatically assigned to the project’s owner (creator) or application’s creator but can also be manually assigned.
  • Manages a specific project or application.
Contributor Is able to initiate tests, triage issues, and perform analysis for a project.  
Observer Has read-only access to the project.
  • Can create reports for applications that they are given permission to view.
Note: If a user has been assigned multiple roles for a project as a member of a group and/or as an individual, they will have the highest level of access assigned.
Note: Black Duck strongly recommends the use of secure authentication techniques like SSO with your Coverity on Polaris implementation for interactive web-based logins. If you have trouble setting this up or cannot implement SSO in your organization, open a support case by signing in to the Black Duck Community site.
CAUTION:
Always disable users who have left your organization or who otherwise no longer need access to Coverity on Polaris. Unauthorized, malicious actors could use the credentials to access your organization's information. If you don't manage users by SSO, you must disable them manually. See Disabling a User.