VCS organization assets
Cortex Cloud Application Security automatically discovers every connected Version Control System (VCS) organization, establishing it as the foundational, top-level governance boundary for your software supply chain.
Prerequisites
Before viewing and managing VCS organization assets, verify the following:
License
An active Cortex Cloud license with Application Security entitlements
RBAC role
The AppSec Admin or SOC Analyst role, or an equivalent custom role with asset inventory and issue management permissions
VCS integration
At least one Version Control System (GitHub, GitLab, Bitbucket, Azure DevOps) integrated and active. VCS organizations are discovered through active VCS integrations
Core capabilities and scope
Discovery and visibility: Automatically identifies organizations via active integrations, capturing their unique identity, provider, and URL
Aggregated posture: Calculates the collective security health across all child entities to determine the organization's overall posture
Scope constraints: The asset represents the organization as a whole; it does not represent individual repositories, specific CI/CD pipelines, or business applications
Key achievements
Code-to-Cloud lineage root: The VCS organization acts as the starting point of the Code-to-Cloud graph. All downstream assets inherit their governance scope (policies, compliance frameworks, and business criticality) from this parent node.
Policy propagation: Organization-level policies automatically flow to all child repositories, ensuring consistent security standards across the environment.
Relationship model
The VCS organization is the root node of the asset hierarchy, interacting with other assets as follows:
Child - Repository: Repositories inherit organization-level policies and compliance scopes. Their individual security findings aggregate up to the organization's overall health profile.
Child - CI/CD Instance: CI/CD platforms associated with the organization (e.g., GitHub Actions for a GitHub org) inherit the VCS provider type and organizational context.
Sibling - VCS Organization: Other VCS organizations within the same tenant. They operate side-by-side but maintain completely independent policy scopes, governance boundaries, and health profiles.
Next steps
Last updated
Was this helpful?
