Skip to content

docs(psirt): who can use PSIRT, and why the permission beats the role - #15741

Merged
Maffooch merged 1 commit into
devfrom
docs/psirt-access-permission
Aug 19, 2026
Merged

docs(psirt): who can use PSIRT, and why the permission beats the role#15741
Maffooch merged 1 commit into
devfrom
docs/psirt-access-permission

Conversation

@devGregA

Copy link
Copy Markdown
Contributor

Description

Documents who can use PSIRT, alongside a Pro change that adds a PSIRT configuration
permission.

Until now the module admitted a superuser or a global Maintainer/Owner and nobody
else, so the page had nothing to say about access beyond the feature flag and the
licence. With a PSIRT-specific permission available, the docs can say the thing that
actually matters: prefer the permission, because a global Maintainer role is write
access to every asset in the instance — granting it so somebody can read advisories
hands them the rest of the product too.

Covers:

  • the three routes in, and which one to prefer;
  • the View / Change split, and that View is genuinely read-only;
  • that the licence is checked before any of it and is not a permission — with no
    PSIRT Advisory Engine entitlement the module is closed to everyone, superusers
    included;
  • that the permission only appears in the picker while the PSIRT feature flag is on.

Docs-only: no code changes.

PSIRT admitted a superuser or a global Maintainer/Owner and nobody else, so the
docs had nothing to say about access beyond the feature flag and the licence. With
a PSIRT configuration permission now available, the page can say the thing that
matters: prefer the permission, because a global Maintainer role is write access to
every asset in the instance and granting it to hand somebody PSIRT hands them the
rest of the product too.

Covers the view/change split, that View is genuinely read-only, that the licence is
checked before any of it and is not a permission, and that the permission only
appears in the picker while the PSIRT flag is on.
@github-actions github-actions Bot added the docs label Aug 19, 2026
@Maffooch Maffooch added this to the 3.3.0 milestone Aug 19, 2026
@Maffooch
Maffooch merged commit ad64239 into dev Aug 19, 2026
23 checks passed
@Maffooch
Maffooch deleted the docs/psirt-access-permission branch August 19, 2026 23:07
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants