ASSOCIATED DRATA CONTROL
This test is part of the Only Authorized Employees Change Code control that ensures your company version control system only allows approved employees to make changes to code on a branch in which they have approval rights.
WHAT TO DO IF A TEST FAILS
If Drata finds users with write access to your version control system that are not current employees/contractors the test will fail. With a failed test you will receive a list of users within your version control system that have write access but do not appear to have matching company accounts.
To remediate a failed test, you will need to either create IdP accounts for these version control system users or revoke their write access to the version control System repositories.
STEPS TO REMEDIATE
On Version Control Provider
Log in as an admin
Navigate to your project(s)
Navigate to your user(s)
Verify user privileges for all accounts.
On Drata
Navigate to the 'Manage Account' page for your Version Control provider
Ensure that the 'write' access flag is enabled
Note: By default, any user in the 'Developer/Maintainer/Owner' category will be reflected on the list in Drata. Users in the 'Guest/Reporter' category will not be reflected.