Organization Admins can set the default policies assigned to applications, projects, and branches in your portfolio, and can choose what types of branches default policies are assigned to.
Policy inheritance
The default policies set at the organization level are automatically applied to applications, projects, and branches in your portfolio, but can be overridden. The policies assigned to applications, projects, and branches take precedence:
- Policies assigned to an application override your organization's default policies
- Policies assigned to a project override organization and application-level policies
- Policies assigned to a branch override organization, application, and project policies
When policy assignments change at a higher level, the change is automatically applied to all lower levels that have not been overridden.
To check how many projects and branches are using your organization's default policies throughout your portfolio, go to . At the bottom of each panel, the number of projects and branches using the default policies is displayed. For example "3 out of 3 DAST projects and 43 out of 50 branches inherit these settings".
Users with access to application and project settings can check how many projects/branches inherit your organization's default policies.
- For an application, go to Portfolio, select an application, and go to Settings.
- For a project, go to Portfolio, select an application, select a project, and go to Settings.
When Inherited appears next to a policy type, the policies that apply to the application (example below) or project are inherited.
Default and non-default branches
Organization Admins can control what types of branches default policies are applied to (or prevent default policies from being assigned to branches altogether). See Control how default policies are applied to branches for more information.