Coverage
The AppSec Coverage page provides centralized visibility into security scanner deployment across the SDLC. Monitor asset health, identify gaps, and orchestrate onboarding.
The AppSec Coverage page is the centralized interface for understanding and managing security scanner coverage across the application development ecosystem. The Coverage page visualizes which assets (VCS repositories, CI/CD pipelines, and container image repositories) are scanned by which security scanners, identifies coverage gaps, and enables direct action to close those gaps.
Core benefits and use cases
Reduce coverage gaps and visibility: Eliminate blind spots by aligning discovered assets with active scanners
Identify onboarded vs. partially onboarded VCS and third-party integrations
Monitor SAST, SCA, Secrets, IaC, and Malware scanner active status across the codebase
Onboarding and maturity acceleration: Direct scanner activation and asset onboarding to improve security posture
Evaluate stage-specific maturity to enable targeted improvements at each phase of the SDLC
Understand global and application-specific security scores to prioritize onboarding efforts
Compliance, guardrails, and health: Ensure scanners are functional and policies are enforced for audit readiness
Verify which security policies and guardrails are applied and assess their effectiveness
Surface scan failures to prevent false confidence in compliance metrics
Prerequisites
Before using the AppSec Coverage page, verify the following:
Cortex Cloud license: An active Cortex Cloud license with Application Security entitlement
RBAC role: AppSec Admin role for full access (view and edit). DevSecOps and Developer roles have view-only access
Data Sources Configured: At least one VCS, CI/CD, or container registry data source onboarded to Cortex Cloud
Scanners enabled: At least one security scanner (integral or third-party) activated on onboarded asset
RBAC permissions
AppSec Admin
Full access
Yes
Yes
Yes
Yes
DevSecOps
View only
Yes
No
No
No
Developer
View only
Yes
No
No
No
Last updated
Was this helpful?
