Organizations
An organization is a distinct entity: your business, a specific department within it, or one of your customers. All actions, tasks, Explorers, scans, and other objects that runZero manages belong to a specific organization and are isolated from each other.
Switch your active organization with the dropdown at the top right of the runZero Console. If your default role is Viewer or higher, select All Organizations from the dropdown to see the data for all of your organizations in the Dashboard and Inventory. The Queries page also supports the All Organizations view. Pages that do not support it stay hidden until you select a single organization.
runZero Community Edition is limited to a single organization.
Use cases for organizations
It’s common to segment your assets across multiple organizations for one of these reasons:
- RBAC limits users to the assets in the organizations they’re added to, and in those organizations’ children.
- Environments such as development and production can stay in separate pools.
- Customers of a service provider generally get one organization each.
Creating organizations
Create, modify, and deactivate organizations from the organizations section of the console: click the Organizations link under Global Settings.
Organization configurations
- Name is the name of the organization.
- Parent organization makes this a sub-organization, with nesting limited to three levels. Permissions are inherited based on most privilege.
- Description describes the organization.
- Stale asset expiration sets the number of days before stale assets are removed from the inventory. It applies to online and offline assets not seen within that many days.
- Offline asset expiration sets the number of days before offline assets are removed from the inventory. It applies to offline assets not seen within that many days.
- Stale integration attributes expiration sets the number of days before stale integration attributes are removed from the inventory. You can optionally keep the latest set of integration attributes per source, even when it is older than the threshold.
- Stale vulnerability expiration sets the number of days since last seen before stale vulnerabilities, including archived ones, are permanently removed from the inventory.
- Enable vulnerability archiving (default: enabled) applies to all vulnerabilities being removed from the active inventory. When disabled, vulnerabilities are deleted instead of archived. Archived metadata (such as suppression state and the original first seen date) is not retained if the vulnerability returns. Disabling this setting disables
Stale vulnerability archive. - Stale vulnerability archive (default: 0, disabled) sets the number of days since last seen before stale vulnerabilities are archived and removed from the active inventory. Set it lower than the stale vulnerability expiration.
- Scan data expiration sets the number of days before completed scans are removed from the platform. It applies to the scan task metadata as well as the raw data files and change reports.
Projects
A project is a special type of organization for temporary use. Projects behave like organizations and can have sites defined within them. The differences: projects cannot be parents of organizations or other projects, they automatically become read only after 30 days, and they are automatically deleted after 90 days. Organizations let you customize expiration times; project expiration times are fixed.
Your runZero license includes up to five times as many project assets as licensed live assets. For example, a license for 1,000 live assets allows up to 5,000 project assets in total. The license information page in the runZero console shows the total number of assets in organizations and projects.
If you decide to keep a project indefinitely, convert it into an organization.
Organizations support custom data retention settings that you can edit to fit your requirements.
Organization and project details
Click the name of an organization or project to open its details page. It shows basic details about the organization or project, along with its place in the organization hierarchy.