VCS collaborators as assets
The VCS Collaborator (collaborators) asset inventory provides a centralized view of all collaborators (users) who interact with VCS repositories, CI/CD pipelines, and related assets. The platform enables efficient discovery and management of these assets, providing insights and analysis to contextualize their importance within your ecosystem and assess their risk posture. You can directly access related issues and findings within the collaborator asset inventory, allowing you to prioritize and remediate them without navigating to a separate remediation section.
How to access collaborator assets
To access Collaborator assets, under Identity, select Human Identities → select VCS Collaborator from the Type filter.
Investigate Collaborator asset information
Click an asset in the inventory table to open its side card, providing in-depth information organized into several tabs.
The Collaborator asset summary, displayed at the top of the card, provides concise details about the collaborator, such as their name and the version control system that the collaborator is associated with.
The Overview tab summarizes the collaborator highlights and properties.
Highlights include:
Critical/High issues: An aggregation of critical and high issues associated with the collaborator
New: Whether the collaborator was recently added to the VCS organization
Inactive: Indicates whether the collaborator has had no commits within the last time period
Properties include:
Risk Summary: The amount of risks associated with the collaborator grouped by category (cases, issues and findings) and their severity level
Asset details, including Asset Id, Asset Types and Asset Groups associated with the collaborator
Visibility timeline: When the collaborator was first and last detected
Identity and Affiliation:
Username: the alias associated with the collaborator
User Type: The classification of the collaborator's account (such as individual user, service account, bot), indicating the nature of their access and activity
VCS Organization: The specific version control system organization to which the collaborator belongs or has access
Emails: "The email addresses associated with the collaborator's account, used for communication and notifications
Access and Activity:
Team Membership: The teams or groups within the VCS Organization to which the collaborator belongs, defining their access permissions and collaborative roles
Last Commit: The timestamp of the collaborator's most recent commit to a repository within the associated VCS Organization, indicating their recent activity
The Highlights section and other asset properties only display attributes when their corresponding indicators are present. For example, if an asset is not deployed, its deployment-related attributes will not show up; similarly, if there are no detected issues, those highlights or properties will not appear.
The Access tab provides a list of assets that a VCS Collaborator has access to within your environment. It details the specific assets they can interact with, the level of permission granted, and the timestamp of their most recent code commit to that asset.
Manage Collaborator assets
You can perform the following actions collaborator assets.
Asset actions
Right-click on an asset in an inventory table to access the Actions menu, where you can perform the following actions:
Open in new tab: Opens the description tab of the asset for detailed analysis of the issue
View asset data: Opens a new pop-up window displaying the data retrieved for the asset during the most recent scan in either JSON (default) or tree view. This raw data provides a comprehensive and unformatted view of the asset's properties and attributes as they were initially ingested
Copy text to clipboard: Copies the selected text to the clipboard
Copy entire row: Copies the entire selected row data
Show/hide rows: Stand on data in a row and filter the entire inventory to show or hide assets based on the selected attribute
Open in Cortex Assistant/Open in Cortex Agentic Assistant: Opens the repository in Cortex Assistant or Cortex Agentic Assistant.
Export asset data: Click the download icon (showing Export to file when hovering over the icon) in the top right of any asset page to export the asset data
View Dashboard: Redirects to the Application Security dashboard
Last updated
Was this helpful?
