Skip to content

[docs] asset/organization in Pro#13848

Merged
Maffooch merged 7 commits intoDefectDojo:bugfixfrom
paulOsinski:docs-hierarchy
Dec 8, 2025
Merged

[docs] asset/organization in Pro#13848
Maffooch merged 7 commits intoDefectDojo:bugfixfrom
paulOsinski:docs-hierarchy

Conversation

@paulOsinski
Copy link
Copy Markdown
Contributor

@paulOsinski paulOsinski commented Dec 8, 2025

adds documentation for upcoming Asset/Organization features in DefectDojo Pro

[sc-12207]

* RBAC scopes have not changed within this system; each Asset is still considered an individual object for the purposes of assigning permissions. No new RBAC inheritance has been created.
* Giving a user access to an entire Organization will still give that user access to all Assets contained within that Organization (as with Product Types).
* Giving a user access to a single Asset does not give that user access to any related Parent or Child Assets, nor access to the Organization.
* There is no limit to the number of Parent/Child relationships that can be created.Theoretically, you could represent a repository's entire directory structure with separate Assets if you wished.
Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Are we confident this is a future proof statement? Suppose if at some point we want to do cascading of permissions or have fancy cross Asset deduplication we might be unhappy that there is not limit to the "depth" of the hierarchy.

Copy link
Copy Markdown
Contributor Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

For now, yes. The feature is still in beta so there may be changes down the line, but parent/child relationships are purely for asset tree visualization and filtering right now.

Copy link
Copy Markdown
Contributor

@mtesauro mtesauro left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Approved

paulOsinski and others added 2 commits December 8, 2025 13:40
…ests/pro_assets_organizations.md

Co-authored-by: Cody Maffucci <46459665+Maffooch@users.noreply.github.com>
…ests/pro_assets_organizations.md

Co-authored-by: Cody Maffucci <46459665+Maffooch@users.noreply.github.com>
@paulOsinski paulOsinski requested a review from Maffooch December 8, 2025 18:45
@Maffooch Maffooch merged commit 3b1b5da into DefectDojo:bugfix Dec 8, 2025
150 of 151 checks passed
Maffooch added a commit to valentijnscholten/django-DefectDojo that referenced this pull request Feb 16, 2026
* add asset/org info

* remove ref to P/PT nestability

* change screenshot

* add contact email

* Update docs/content/en/working_with_findings/organizing_engagements_tests/pro_assets_organizations.md

Co-authored-by: Cody Maffucci <46459665+Maffooch@users.noreply.github.com>

* Update docs/content/en/working_with_findings/organizing_engagements_tests/pro_assets_organizations.md

Co-authored-by: Cody Maffucci <46459665+Maffooch@users.noreply.github.com>

---------

Co-authored-by: Paul Osinski <paul.m.osinski@gmail.com>
Co-authored-by: Cody Maffucci <46459665+Maffooch@users.noreply.github.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Projects

None yet

Development

Successfully merging this pull request may close these issues.

5 participants