Veracode for Team Administrators
Setting up users, teams, and access for your organization
If you're responsible for configuring Veracode access for your organization, this guide is for you. Team Admins and Administrators handle user accounts, role assignments, team structure, and application profile setup — the foundation that everything else depends on.
Veracode Platform Roles Reference
Understanding roles is the most important part of your job. Assigning the wrong role is the most common cause of "I can't see my results" support requests.
| Role | What They Can Do |
|---|---|
| Administrator | Full platform access — create users, manage teams, configure everything. Note: Administrators cannot approve or reject mitigation proposals — that requires the separate Mitigation Approver role. |
| Security Lead | View all applications and scan results, view Analytics for all apps, manage policies |
| Mitigation Approver | Approve or reject mitigation proposals on findings — a dedicated role, separate from Security Lead |
| Policy Administrator | Create and manage security policies in the Veracode Platform |
| Creator | Create application profiles and submit scans for team applications |
| Submitter | Submit scans for existing applications in their teams |
| Reviewer | View scan results for applications in their teams |
| Team Admin | Edit and manage users within the teams they manage (cannot create new users — user creation requires the Administrator role) |
| Executive | View Analytics and reports across all applications (read-only) |
| Analytics Creator | Create and edit custom Analytics dashboards |
Creating User Accounts
- Manual — Admin section in the Veracode Platform. Assign roles and team membership at creation. docs.veracode.com/r/t_create_users
- Bulk via REST API — Identity REST API for creating and managing users programmatically. docs.veracode.com/r/c_identity_intro
- SSO/SAML — Configure SAML-based authentication so users sign in with your identity provider. docs.veracode.com/r/about_saml
Setting Up Teams
Teams control which users have access to which applications. Set up teams before adding users, then assign users during account creation.
- Docs: Create and Manage Teams
Tip: Structure teams to mirror how your organization owns code — by product, business unit, or development team. This ensures scan results are only visible to the people responsible for them.
Creating Application Profiles
Every application you scan in Veracode needs an application profile. The profile defines the application's name, business criticality, policy, and team ownership.
- In the Veracode Platform, go to My Portfolio > Applications.
- Select Add Application.
- Fill in the application name, description, and business criticality.
- Assign the application to a team and a security policy.
- Save the profile.
Setting Business Criticality
The business criticality rating (Very High, High, Medium, Low, Very Low) affects how Veracode calculates risk scores and how policies are applied. Set this thoughtfully — it influences what counts as a priority finding.
- Docs: Business Criticality
API Service Accounts for Automation
For pipeline integrations and automated scanning, create API service accounts (non-human users) rather than using personal API credentials. Assign only the specific API roles needed.
- Docs: Create an API Service Account
- Docs: API Roles
Useful Resources
Learning Paths
Go deeper with these step-by-step learning paths on Veracode Docs:
← Back to the Getting Started Guide | ← Back to the Onboarding Hub
.png)