Waivers

Waivers provide a method of progressing your workflow if failures are holding up your work. For example, if promotions from one stage to another in your SDLC are failing, you can get a waiver that will allow promotion without evaluation of the criteria defined for promotion to succeed. Waivers require justification and approval, are effective for limited time periods that you define, and cover a scope that you choose. For example, a waiver can apply at the stage gate level for an application, meaning that for a selected application, none of the policies at a chosen stage gate will be evaluated.

Waivers may apply to different resource scopes, such as different levels or your organization, specified findings, policies or rules, or lifecycle stage gates.

For a waiver to be valid, it must go through an approval process that requires a requester and an approver. Requesters, for example, might be developers, release managers, or a VP R&D, while approvers might be policy managers, a VP R&D, or a Chief Information Security Officer. A requester can create and cancel requests for waivers. The approver can approve and reject requests and can also revoke a request after it has been approved.

To use waivers, you must have one of the following roles defined in JFrog Platform Administration:

  • To request waivers and cancel requests: Read Policies role
  • To approve, reject, and revoke waivers: Manage Policies role

This section describes the waiver process and the tasks required for managing waivers, including:

What's Next?

Learn how to Request a Waiver .



Did this page help you?