Veracode for Team Administrators

Setting up users, teams, and access for your organization

If you're responsible for configuring Veracode access for your organization, this guide is for you. Team Admins and Administrators handle user accounts, role assignments, team structure, and application profile setup — the foundation that everything else depends on.


Veracode Platform Roles Reference

Understanding roles is the most important part of your job. Assigning the wrong role is the most common cause of "I can't see my results" support requests.

Role What They Can Do
Administrator Full platform access — create users, manage teams, configure everything. Note: Administrators cannot approve or reject mitigation proposals — that requires the separate Mitigation Approver role.
Security Lead View all applications and scan results, view Analytics for all apps, manage policies
Mitigation Approver Approve or reject mitigation proposals on findings — a dedicated role, separate from Security Lead
Policy Administrator Create and manage security policies in the Veracode Platform
Creator Create application profiles and submit scans for team applications
Submitter Submit scans for existing applications in their teams
Reviewer View scan results for applications in their teams
Team Admin Edit and manage users within the teams they manage (cannot create new users — user creation requires the Administrator role)
Executive View Analytics and reports across all applications (read-only)
Analytics Creator Create and edit custom Analytics dashboards

Creating User Accounts


Setting Up Teams

Teams control which users have access to which applications. Set up teams before adding users, then assign users during account creation.

Tip: Structure teams to mirror how your organization owns code — by product, business unit, or development team. This ensures scan results are only visible to the people responsible for them.


Creating Application Profiles

Every application you scan in Veracode needs an application profile. The profile defines the application's name, business criticality, policy, and team ownership.

  1. In the Veracode Platform, go to My Portfolio > Applications.
  2. Select Add Application.
  3. Fill in the application name, description, and business criticality.
  4. Assign the application to a team and a security policy.
  5. Save the profile.

Setting Business Criticality

The business criticality rating (Very High, High, Medium, Low, Very Low) affects how Veracode calculates risk scores and how policies are applied. Set this thoughtfully — it influences what counts as a priority finding.


API Service Accounts for Automation

For pipeline integrations and automated scanning, create API service accounts (non-human users) rather than using personal API credentials. Assign only the specific API roles needed.


Useful Resources


Learning Paths

Go deeper with these step-by-step learning paths on Veracode Docs:


← Back to the Getting Started Guide | ← Back to the Onboarding Hub