For the complete documentation index, see llms.txt. This page is also available as Markdown.

VCS organization assets

Cortex Cloud Application Security automatically discovers every connected Version Control System (VCS) organization, establishing it as the foundational, top-level governance boundary for your software supply chain.

Prerequisites

Before viewing and managing VCS organization assets, verify the following:

Prerequisite
Description

License

An active Cortex Cloud license with Application Security entitlements

RBAC role

The AppSec Admin or SOC Analyst role, or an equivalent custom role with asset inventory and issue management permissions

VCS integration

At least one Version Control System (GitHub, GitLab, Bitbucket, Azure DevOps) integrated and active. VCS organizations are discovered through active VCS integrations

Core capabilities and scope

  • Discovery and visibility: Automatically identifies organizations via active integrations, capturing their unique identity, provider, and URL

  • Aggregated posture: Calculates the collective security health across all child entities to determine the organization's overall posture

  • Scope constraints: The asset represents the organization as a whole; it does not represent individual repositories, specific CI/CD pipelines, or business applications

Key achievements

  • Code-to-Cloud lineage root: The VCS organization acts as the starting point of the Code-to-Cloud graph. All downstream assets inherit their governance scope (policies, compliance frameworks, and business criticality) from this parent node.

  • Policy propagation: Organization-level policies automatically flow to all child repositories, ensuring consistent security standards across the environment.

Relationship model

The VCS organization is the root node of the asset hierarchy, interacting with other assets as follows:

  • Child - Repository: Repositories inherit organization-level policies and compliance scopes. Their individual security findings aggregate up to the organization's overall health profile.

  • Child - CI/CD Instance: CI/CD platforms associated with the organization (e.g., GitHub Actions for a GitHub org) inherit the VCS provider type and organizational context.

  • Sibling - VCS Organization: Other VCS organizations within the same tenant. They operate side-by-side but maintain completely independent policy scopes, governance boundaries, and health profiles.

Next steps

Last updated

Was this helpful?