For the complete documentation index, see llms.txt. This page is also available as Markdown.

Coverage

The AppSec Coverage page provides centralized visibility into security scanner deployment across the SDLC. Monitor asset health, identify gaps, and orchestrate onboarding.

The AppSec Coverage page is the centralized interface for understanding and managing security scanner coverage across the application development ecosystem. The Coverage page visualizes which assets (VCS repositories, CI/CD pipelines, and container image repositories) are scanned by which security scanners, identifies coverage gaps, and enables direct action to close those gaps.

Core benefits and use cases

  • Reduce coverage gaps and visibility: Eliminate blind spots by aligning discovered assets with active scanners

    • Identify onboarded vs. partially onboarded VCS and third-party integrations

    • Monitor SAST, SCA, Secrets, IaC, and Malware scanner active status across the codebase

  • Onboarding and maturity acceleration: Direct scanner activation and asset onboarding to improve security posture

    • Evaluate stage-specific maturity to enable targeted improvements at each phase of the SDLC

    • Understand global and application-specific security scores to prioritize onboarding efforts

  • Compliance, guardrails, and health: Ensure scanners are functional and policies are enforced for audit readiness

    • Verify which security policies and guardrails are applied and assess their effectiveness

    • Surface scan failures to prevent false confidence in compliance metrics

Prerequisites

Before using the AppSec Coverage page, verify the following:

  • Cortex Cloud license: An active Cortex Cloud license with Application Security entitlement

  • RBAC role: AppSec Admin role for full access (view and edit). DevSecOps and Developer roles have view-only access

  • Data Sources Configured: At least one VCS, CI/CD, or container registry data source onboarded to Cortex Cloud

  • Scanners enabled: At least one security scanner (integral or third-party) activated on onboarded asset

RBAC permissions

Role
Access Coverage page
View coverage data
Configure scanner relevancy
Onboard assets
Activate scanners

AppSec Admin

Full access

Yes

Yes

Yes

Yes

DevSecOps

View only

Yes

No

No

No

Developer

View only

Yes

No

No

No

Last updated

Was this helpful?