docs: notifications follow every organization membership - #15628
Open
devGregA wants to merge 1 commit into
Open
Conversation
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Description
Follow-up to #15619 (organization types + non-exclusive membership), documenting one behavior that section did not yet cover: notification fan-out follows every Organization membership, not only an Asset's primary Organization.
Notifications about an Asset — and its Engagements, Tests, and Findings — now reach the members of every Organization the Asset belongs to (still subject to each user's own notification preferences), matching the access rule documented directly above it. Pinning an Asset into a Compliance Scope Organization therefore makes that scope's members an audience for its findings; removing the membership removes them again.
Behavior is gated by the same deployment flag as the rest of non-exclusive membership (
DD_V3_ORGANIZATION_NONEXCLUSIVE, off by default), so default deployments are unchanged.One paragraph added to
docs/content/asset_modelling/engagements_tests/PRO__organizations.md(Membership and access). Text only, no screenshots.Checklist
devline, paired with the DefectDojo Pro change for the same release.