The risk owner¶
This track is for the CISO, the authorizing official, the program security lead, or whoever answers when a customer's security team or an auditor asks how a release was approved. You do not need to work in GitLab and you do not review packages. Attest gives you a view of the whole portfolio and a complete record of every decision made on it.
What you are responsible for¶
- The posture: which containers are authorized, which are pending, which are blocked, and how much accepted risk each one carries.
- The record: every decision, who made it, when, and on what evidence.
- The policy: the set of gates and thresholds your reviewers decide against.
- The answer, when someone outside the team asks.
What you do not have to do¶
The viewer role never asks you to connect a GitLab account; it is read only. You will not have to reconcile a scan report against a separate decision log, because in Attest they are the same record. And you will not have to ask a reviewer what they meant, because the basis they wrote is stored with the decision.
Getting started¶
Sign in. With the viewer role you land on Security posture. The tiles at the top count what is authorized, what is waiting on a reviewer, what is blocked with engineering, and what is still in the pipeline. Below them, the list is sorted by open risk with the worst first, and each row shows the container, its version, its state, and who decided it.
Open any container to see the package exactly as the reviewer saw it, including the basis they wrote for each accepted risk.
Pages in this track¶
- Security posture explains the portfolio view.
- The record explains what a decision contains and where it is kept.
- Exports and evidence covers what to hand an auditor.
- Program deployments covers dedicated tenancy, IL5+, and air gapped environments.