Building your inventory
The quality and completeness of your organization’s application definitions are essential
for IBM® Concert ’s ability to surface
vulnerabilities, compliance issues, and other details about your operational health. You can define
your applications and environments from ingested components or generate SBOM files in the supported
formats. With this information, Concert provides a
holistic view of your application and environment topology.
Access control for applications, repositories, and build artifacts Concert applies role-based access control (RBAC) across applications, repositories, and build artifacts. Access to these assets is determined by the user’s role (L1 admin or L1 user) and their assigned access to specific applications or environments.Application and environment name restrictions This section provides guidelines for naming applications and environments when using the Concert API.Generating ConcertDef SBOMs To build your application topology, you can generate and import SBOM files in the custom ConcertDef (Concert -defined) schema containing details about your application components and dependencies.Defining applications in IBM Concert You can define applications in Concert by using multiple approaches, depending on how your application data is available and how you prefer to build application inventory. These methods support SBOM-based definition, component-based selection, UI-guided setup, and automatic discovery.Updating an application definition Applications can evolve over time as new components, repositories, or environments are introduced. In IBM Concert, you can update an existing application definition by editing it in the UI, modifying the application SBOM, or updating associations through the API.Defining an environment from resources One method for defining your environments is to select relevant build artifacts from resources. The resource library is populated based on existing data ingestion jobs that pull application and environment data from your third-party tools and services.Importing data to Concert There are multiple methods you can use to import application and dimensional data to your Concert instance. You can choose the approach that best fits your workflow, automated ingestion, API-based uploads, or UI-guided configuration.Ingesting data at scale in Concert When you ingest significant volumes of data into your Concert instance, for example, large code scans or many SBOM files, you may experience delays or failures if your deployment is not configured to support high throughput. This topic provides customer‑facing best practices for configuring Concert and its database to reliably ingest data at scale.Creating a data ingestion job The quality and completeness of your organization’s application definitions are essential to Concert 's ability to surface vulnerabilities, compliance issues, and other valuable insights. One way to share your application-related data with Concert is by creating an ingestion job.Exporting an application or environment As needed, you can export an application or environment defined in your Concert instance, and then import it into a new Concert instance as part of a migration or replication process. The output of the export will be a .tar file and is stored in the LZ bucket.Importing an application or environment After exporting an application or environment definition (.tar file), you can import it into a new Concert instance as part of a migration or replication process. Upon import, the data is reassessed and appears in your Inventory and Arena view . Viewing a history of applications and components You can view the build and deployment history of your applications in Concert , including the associated build artifacts and repositories. This feature provides a comprehensive view of the changes to build artifacts and repositories over time, as well as the associated scans and trends.