Skip to main content
The Vidoc web app is for AppSec teams, administrators, and other users who manage findings. Developers usually see Vidoc in pull request (PR) comments. Refer to Pull request reviews.

Sign in

Open app.vidoc.dev or your custom deployment URL. For an on-premises installation, use the web app URL from your admin. Follow the sign-in steps for your deployment:
  1. Open https://app.vidoc.dev.
  2. Sign in with a passwordless email link or with Google. Vidoc accepts only verified email addresses.
  3. If you have no organization, Vidoc starts the onboarding. You create an organization and become its admin. Refer to Quickstart.
If another user invited you, Vidoc shows You’ve been invited. Click Accept to join the organization, or Decline to create your own organization.

Organizations and projects

An organization contains your users, your source code platform connections, and your projects. A project contains repositories, findings, and Memory. Most pages show the data of the current project.
  • Vidoc Cloud: you can be a member of more than one organization. To go to a different organization, open the user menu and click Change organization. When you get an invitation to one more organization, a banner shows Review.
  • Self-hosted: the installation has one organization.
To select a project, use the project switcher at the top of the sidebar. The same menu has these items:
Findings, Insights, AI Chat, and Memory need the Enterprise plan on Vidoc Cloud. Included in self-hosted installations. On other plans, the sidebar shows these items in an Enterprise only group, and you cannot open them.
The user menu shows only the items that your role and your deployment allow:
  • Account: SCM usernames.
  • Organization settings: Integrations, Scans (self-hosted only), Audit logs, Slack Integration (Vidoc Cloud only), Members, Billing (Vidoc Cloud only).
  • Change organization (Vidoc Cloud only) and Sign out.
For each settings page, refer to Settings.

Roles

Each user has one role in the organization: Admin, Security Engineer, Developer, or Read Only. An admin sees all projects. Other roles see only the projects that an admin gives them access to. To change roles and project access, refer to Members.
This table describes web app permissions. PR and Slack interactions have separate access rules, including project-wide code access and finding changes through the bot. Before enabling them, read PR permissions, Slack access, and Supported platforms.