This guide is for organizations looking to test their integrations in a non-production environment. It provides detailed steps to populate an in-house pentest with test findings.
:::info Users must have the Team Member role to create a pentest.
:::
:::info Refer to the Pentest Team Member section of the product documentation for more details.
:::
Open the Pentests page from the sidebar and click Create Pentest.
:::info If the Create Pentest button is disabled, the user role must be changed to Team Member. Learn how to switch the user role for an In-House Pentest.
:::
Click Get Started if the In-House Pentest Beta feature is not yet enabled for your organization.
:::info Skip this step if the In-House Pentest Beta feature is already enabled.
:::
:::info Skip this step if the In-House Pentest Beta feature is already enabled.
:::
Select the In-House Pentest type and asset you want to test, then click Continue.
:::info You can create a dedicated asset for testing or use an existing one.
:::
:::info Renaming the pentest is optional but helps distinguish test pentests. Click the pencil icon next to the pentest name and confirm with Done.
:::
:::info The input content is irrelevant.
:::
:::info You can check the I’m a point of contact for this pentest checkbox.
:::
:::info Refer to the public documentation for more about user roles and associated permissions.
:::
:::info The application will automatically reload after changing your pentest collaborator role.
:::
:::info The user must have the In-House Pentester role.
:::
:::info Refer to the In-House Pentester section of the product documentation for more details.
:::
:::info The pentest should be in the planned state.
:::
:::info The pentest state changes to live.
:::
:::info If the Launch Pentest button is disabled, the user role must be changed to In-House Pentester. Learn how to switch the user role for an In-House Pentest.
:::
:::info The pentest must be live to submit findings.
:::
:::info The user must have the In-House Pentester role.
:::
:::info Refer to the In-House Pentester section of the product documentation for more details.
:::
:::info If the Submit Finding button is disabled, the user role must be changed to In-House Pentester. Learn how to switch the user role for an In-House Pentest.
:::
Provide the following information to create a test finding:
:::info The input content is irrelevant but must meet validation constraints. For example, the severity must contain at least 3 characters.
:::
Change the finding state to Pending Fix from the State dropdown and submit the evaluation.
Set the Likelihood and the Business Impact values by clicking the circles (●) and then the Submit evaluation button.
The pentest finding is now in the Pending Fix state.
:::info Once you have added test findings to the In-House Pentest, remember to switch the user role back to Team Member. If you remain in the In-House Pentester role, certain integration-related UI elements, such as external tickets or the Integrations tab, will be hidden.
:::