---
title: "Create Test Finding"
description: "This guide is for organizations looking to test their integrations in a non-production environment. It provides detailed steps to populate an in-house pentest with test findings."
canonical_url: "https://cobalt-io.brainfish.ai/articles/create-test-finding-370hXblrR6"
md_url: "https://cobalt-io.brainfish.ai/articles/create-test-finding-370hXblrR6.md"
---
# Create Test Finding

This guide is for organizations looking to test their integrations in a non-production environment. It provides detailed steps to populate an in-house pentest with test findings.

## **Prerequisites**

* Cobalt staff must have created and set up a test organization for you. If not, please contact your customer success manager.
* You must be invited to the test organization, accept the invitation, and have an **Owner** role.

 ![](https://cobalt-io.brainfish.ai/api/attachments.redirect?id=df85d263-22b4-4945-a1c6-24f292ed5628)

## **Create In-House Pentest**


:::info
Users must have the **Team Member** role to create a pentest.

:::


:::info
Refer to the [Pentest ](https://docs.cobalt.io/en-us/articles/user-roles-and-permissions-oCij6uRrUR#h-pentest-team-member)**[Team Member](https://docs.cobalt.io/en-us/articles/user-roles-and-permissions-oCij6uRrUR#h-pentest-team-member)** section of the product documentation for more details.

:::


1. Open the **Pentests** page from the sidebar and click **Create Pentest**.

    ![](https://cobalt-io.brainfish.ai/api/attachments.redirect?id=3c32fde1-125a-4938-933e-6fce5c6e38e1)


:::info
If the **Create Pentest** button is disabled, the user role must be changed to **Team Member**. Learn how to [switch the user role for an ](https://docs.cobalt.io/en-us/articles/create-test-finding-370hXblrR6#h-switch-the-users-role-of-an-in-house-pentest)**[In-House Pentest](https://docs.cobalt.io/en-us/articles/create-test-finding-370hXblrR6#h-switch-the-users-role-of-an-in-house-pentest)**.

:::


2. Click **Get Started** if the **In-House Pentest Beta** feature is not yet enabled for your organization.

    ![](https://cobalt-io.brainfish.ai/api/attachments.redirect?id=86dd2c48-a0f9-4bfa-8760-28f789c54e5d " =768x576")


:::info
Skip this step if the **In-House Pentest Beta** feature is already enabled.

:::


3. Click **Enter the Beta** to enable the **In-House Pentest Beta** feature.

 ![](https://cobalt-io.brainfish.ai/api/attachments.redirect?id=e31affa0-b354-4ec3-8ddc-eecba206191b " =768x783")


:::info
Skip this step if the **In-House Pentest Beta** feature is already enabled.

:::


4. Select the **In-House Pentest** type and asset you want to test, then click **Continue**.

    ![](https://cobalt-io.brainfish.ai/api/attachments.redirect?id=a9f169b8-e5a1-44f9-923d-d94d963aca6c)  ![](https://cobalt-io.brainfish.ai/api/attachments.redirect?id=2c3cb93f-4013-41ea-ac9c-8674062eada6)


:::info
You can create a dedicated asset for testing or use an existing one.

:::


5. No changes are required on the **Asset** page. Click **Next** to proceed.

 ![](https://cobalt-io.brainfish.ai/api/attachments.redirect?id=63bea084-1181-40d5-993e-73a65cca61f3)


:::info
Renaming the pentest is optional but helps distinguish test pentests. Click the pencil icon next to the pentest name and confirm with **Done**.

:::


6. On the **Requirements** page, set the following fields:

* **Targets**
* **Objectives**
* **Technology stack**

 ![](https://cobalt-io.brainfish.ai/api/attachments.redirect?id=476cef92-05f8-4b17-8bda-3a90adbc2b3b)

 ![](https://cobalt-io.brainfish.ai/api/attachments.redirect?id=a5019a2c-28ca-4839-9e1e-a8dca9337cd2)


:::info
The input content is irrelevant.

:::


7. No changes are required on the **Details** page. Click **Next** to proceed.

 ![](https://cobalt-io.brainfish.ai/api/attachments.redirect?id=0742bf80-9ba9-4421-a08b-60db22003e37)


8. On the **Scope & Plan** page, select the required **Start** and **End** dates, then click **Save & Exit** to create the pentest.

 ![](https://cobalt-io.brainfish.ai/api/attachments.redirect?id=33b7f84f-fa8c-468d-94d8-e7ce6bb0680c)


:::info
You can check the *I’m a point of contact for this pentest* checkbox.

:::


9. The **In-House** pentest is now in the **draft** state. Click **Move to Planned**.

 ![](https://cobalt-io.brainfish.ai/api/attachments.redirect?id=89e09420-a3a4-4686-a640-b830c8c12acd)


10. Confirm by clicking **Move to Planned** in the modal dialog.

 ![](https://cobalt-io.brainfish.ai/api/attachments.redirect?id=17186259-bf4d-4bb8-be58-4e1be0ef2476)

## **Switch the User’s Role of an In-House Pentest**


:::info
Refer to the public documentation for more about [user roles and associated permissions](https://docs.cobalt.io/en-us/articles/user-roles-and-permissions-oCij6uRrUR).

:::


1. Go to the sidebar and select **Pentests**.
2. Choose an **In-House Pentest** from the list.
3. Open the **Collaborators** tab.
4. Click the dropdown for **Role** next to your username and select the desired role for the **In-House Pentest**.

 ![](https://cobalt-io.brainfish.ai/api/attachments.redirect?id=abd744df-2272-40d7-b16d-bfa3681883cb)


:::info
The application will automatically reload after changing your pentest collaborator role.

:::

## **Launch In-House Pentest**


:::info
The user must have the **In-House Pentester** role.

:::


:::info
Refer to the **[In-House Pentester](https://docs.cobalt.io/en-us/articles/user-roles-and-permissions-oCij6uRrUR#h-in-house-pentester)** section of the product documentation for more details.

:::


1. Select **Pentests** from the sidebar.
2. Choose the **In-House Pentest** you want to launch.


:::info
The pentest should be in the **planned** state.

:::


3. Click the **Launch Pentest** button.

 ![](https://cobalt-io.brainfish.ai/api/attachments.redirect?id=f7c34a45-673b-4e61-8f8b-343b4593c90a)


:::info
The pentest state changes to **live**.

:::


:::info
If the **Launch Pentest** button is disabled, the user role must be changed to **In-House Pentester**. Learn how to [switch the user role for an ](https://docs.cobalt.io/en-us/articles/create-test-finding-370hXblrR6#h-switch-the-users-role-of-an-in-house-pentest)**[In-House Pentest](https://docs.cobalt.io/en-us/articles/create-test-finding-370hXblrR6#h-switch-the-users-role-of-an-in-house-pentest)**.

:::

## **Create Test Finding**


:::info
The pentest must be **live** to submit findings.

:::


:::info
The user must have the **In-House Pentester** role.

:::


:::info
Refer to the **[In-House Pentester](https://docs.cobalt.io/en-us/articles/user-roles-and-permissions-oCij6uRrUR#h-in-house-pentester)** section of the product documentation for more details.

:::


1. Select **Pentests** from the sidebar.
2. Choose an **In-House Pentest** from the list to populate with test findings.
3. Click **Submit Finding**.

 ![](https://cobalt-io.brainfish.ai/api/attachments.redirect?id=41fca238-f0e2-4fc9-8b0e-bf39d81fe014)


:::info
If the **Submit Finding** button is disabled, the user role must be changed to **In-House Pentester**. Learn how to [switch the user role for an ](https://docs.cobalt.io/en-us/articles/create-test-finding-370hXblrR6#h-switch-the-users-role-of-an-in-house-pentest)**[In-House Pentest](https://docs.cobalt.io/en-us/articles/create-test-finding-370hXblrR6#h-switch-the-users-role-of-an-in-house-pentest)**.

:::

Provide the following information to create a test finding:

* **Vulnerability type**
* **Description**
* **Proof of Concept**
* **Severity**
* **Suggested fix**

 ![](https://cobalt-io.brainfish.ai/api/attachments.redirect?id=a82a3173-8257-4fb3-9fbf-9a60c4332250 " =1024x419")

 ![](https://cobalt-io.brainfish.ai/api/attachments.redirect?id=c25aae87-2993-433a-a930-378d99afa721)

 ![](https://cobalt-io.brainfish.ai/api/attachments.redirect?id=c8d281a9-423d-4108-9af0-d62479f59500)


:::info
The input content is irrelevant but must meet validation constraints. For example, the severity must contain at least 3 characters.

:::


4. Click **Submit for Triaging** at the bottom of the page when all required information is set.

 ![](https://cobalt-io.brainfish.ai/api/attachments.redirect?id=db6da9a0-3197-430b-b958-69c61da57123)


5. The pentest finding is now in the **Triaging** state.

 ![](https://cobalt-io.brainfish.ai/api/attachments.redirect?id=a36f2738-23bb-434e-928b-d3bc4bffed2e)


6. Change the finding state to **Pending Fix** from the **State** dropdown and submit the evaluation.

    ![](https://cobalt-io.brainfish.ai/api/attachments.redirect?id=ae974dec-4e3f-4a47-8a9f-fa4293e97f7d)
7. Set the **Likelihood** and the **Business Impact** values by clicking the circles (**●**) and then the **Submit evaluation** button.  ![](https://cobalt-io.brainfish.ai/api/attachments.redirect?id=3692c010-a446-4813-8298-2a03e93efb65)
8. The pentest finding is now in the **Pending Fix** state.

 ![](https://cobalt-io.brainfish.ai/api/attachments.redirect?id=f21fbadc-6687-4213-a1d2-acbf048302f4)


9. View all pentest findings.

 ![](https://cobalt-io.brainfish.ai/api/attachments.redirect?id=796b907e-7f81-4ce5-8e76-b746759e48cd)


:::info
Once you have added test findings to the **In-House Pentest**, remember to switch the user role back to **Team Member**. If you remain in the **In-House Pentester** role, certain integration-related UI elements, such as external tickets or the **Integrations** tab, will be hidden.

:::
