User Management | DefectDojo Documentation

User Management

DefectDojo’s user management surface is different in each edition. Pick the section that matches your installation.

DefectDojo Open-Source

Open-source DefectDojo uses the Authorized Users model: a user is given access to a Product or a Product Type by being added to that record’s Authorized Users list. Superusers and staff can see everything.

Authentication on open-source DefectDojo is local username/password plus the password-reset flow.

DefectDojo Pro

DefectDojo Pro uses a role-based system with Members, Groups, and Global Roles. Users can also be granted SSO access through SAML or one of the supported OAuth providers.

Migrating between editions

If you’re moving from open-source’s Authorized Users to Pro’s RBAC, or upgrading from a pre-3.0 open-source release that used RBAC into the current Authorized Users model, see the 3.0 upgrade notes. Existing access is preserved automatically.

All DefectDojo Pro user permissions in detail