Understand and prioritize VCS organization assets
Access, review, filter, and prioritize VCS organization assets.
How to access VCS organization assets
To access VCS organization assets, under Inventory, select All Assets → Code → VCS Organizations.
The VCS Organizations assets page includes a dashboard and an inventory.
VCS organization dashboard
The dashboard includes the following widget:
Providers: Displays connected version control providers, such as GitHub, GitLab, Bitbucket, and Azure DevOps, and the number of organizations found in each provider.
Selecting an item in the widget filters the table accordingly.
VCS organization asset inventory
The following table describes the default exposed properties of the VCS Organization asset table. Select Menu Settings to view additional properties.
VCS Organization Name
The name of the VCS organization as discovered from the VCS integration. The Organization Name serves as the primary identifier for the VCS organization asset.
VCS Organization Provider
The VCS platform hosting the organization, such as GitHub, GitLab, Bitbucket, or Azure DevOps, displayed with a provider icon.
First Observed
The date and time the asset was initially detected and registered into the unified asset inventory during its first scan.
Observation Time
The date and time the asset was last updated, scanned, or seen by the platform's discovery and scanning mechanisms.
VCS Organization URL
The direct web address to the organization within the VCS provider platform. This enables direct navigation from the inventory to the provider console.
Business Application Names
The business applications associated with the asset. VCS organizations inherit these applications from child repositories and CI/CD instances.
Filter and prioritize VCS organizations
The VCS Organizations page displays a table of all VCS organizations. Use the search bar to find specific organizations by name. Apply filters to narrow the inventory by operational and security metadata.
High-priority filtering workflows
Use the following filters to prioritize remediation:
Scope by VCS provider: Use the Provider filter or dashboard widget to isolate a provider, such as GitHub or GitLab. This helps evaluate provider-specific risks and enforce platform security standards
Identify access control risks: Filter by Is MFA needed = No to identify VCS organizations without Multi-Factor Authentication. Prioritize these foundational organization boundaries for review
Next steps
Last updated
Was this helpful?
