The following figure shows an example:
- Your organization contains users and groups.
- A group contains users and other groups.
- A user can belong to more than one group.
Users and groups can either be managed within Coverity on Polaris itself, or you can choose to integrate a SAML 2.0 Identity Provider (IDP).
Managing users and groups within Coverity on Polaris means that all your decisions about access to testing results are logically contained in one place.
Roles
Overview
There are two levels of roles assigned in different ways and govern separate aspects of Coverity on Polaris:
- The Organization Role is assigned once and governs what areas of the site the user has access to outside of Projects.
- The Project Role is assigned per Project and governs what a user can do within that Project.
The Projects that a user can view/access can be determined by either the Organizational Role or the Project membership:
- If the user has an Org Role of Org Admin or Application Manager, they automatically have access and administrative privileges to all Projects in the organization.
- If the user has an Org Role of Contributor or Observer, they will only have access to Projects for which they are a member of (where they can hold the role of Administrator (Project), Contributor or Observer).
Organizational Roles
| User Role | Access * | Definition | Notes |
|---|---|---|---|
| Administrator (Organization) | Global | Manages all of Coverity on Polaris including adding new users, creating groups, SAML integration and service account settings. |
|
| Application Manager | Global | Manages all projects and applications. |
|
| Contributor | Via Membership to Project/Application | Can be assigned as an individual member or group to an application or project role. |
|
| Observer | Via Membership to Project/Application | Can be assigned as an individual member or group to an application or project role. |
|
*Global - Has access to and can manage all projects and applications. Organizational Administrators can add new users/groups and has access to the “My Organization” section.
Via Membership to Project / Application - Has access to assigned projects and/or applications. Users can only view applications that include projects they have been assigned a role for.
- Applications allow members to view summary data and run reports from multiple projects. Members must have a project role to view more detailed individual project information.
- For applications, these roles can view applications that include assigned projects or that they are assigned membership to.
Project Roles (Members)
These are assigned to the individual user or group per project or application. These can be assigned by Organizational Administrator, Application Manager or Project Administrator. See Add and Remove Members for a Project.
| Project / Application Role | Definition | Notes |
|---|---|---|
| Administrator (Project) |
|
|
| Contributor | Is able to initiate tests, triage issues, and perform analysis for a project. | |
| Observer | Has read-only access to the project. |
|