AI SRE Security
Harness AI SRE includes security measures to protect incident data, ensuring confidentiality, integrity, and availability. It integrates with the Harness Platform's security features, including authentication, role-based access control (RBAC), audit trails, and secret management.
Security measures include:
- Data encryption in transit (TLS 1.3) and at rest (AES 256)
- Role-based access controls to restrict incident data
- Secure API authentication for third-party integrations
- Audit logging for compliance tracking
Security measures
Harness AI SRE ensures incident security by restricting access, encrypting data, and logging all activities.
- Access management: Supports authentication via SAML, OAuth, and API tokens.
- Data protection: Encrypts incident metadata, logs, and communication history.
- Automation and runbook security: Ensures that only authorized users execute automated actions.
- Audit and compliance: Logs every action for tracking and compliance reviews.
Security components
- Incident Data Storage
- Secure Automation & Runbooks
- Communication & Webhook Security
Incident data, logs, and automation history are securely stored.
- Data is encrypted and retained per organization policies.
- Access is controlled through RBAC.
Harness AI SRE retains incident logs and history based on your organization's settings.
Runbooks execute predefined automation securely.
- Actions run in a controlled environment.
- API requests require valid authentication.
Runbook executions require API keys or OAuth authentication for third-party integrations.
Harness AI SRE integrates with communication tools and on-call platforms through secure webhooks and APIs.
- Incoming webhooks receive incident alerts.
- Outbound notifications are not permitted.
Operational security
Harness AI SRE ensures security at every stage:
-
Incident creation and logging:
- Incidents are created through authenticated sources (UI, API, webhooks).
- Data is encrypted before storage.
-
Access and role management:
- RBAC controls who can access incidents.
- Authentication via OAuth/SAML is required.
-
Automation execution:
- Actions are logged for compliance.
- Only approved integrations execute via Harness Delegate.
-
Audit and compliance logging:
- Every action is recorded for compliance audits.
- Logs can be exported for security reviews.
-
Third-party integration security:
- OAuth tokens, API keys, and access scopes protect integrations.
- Secure connections use TLS 1.3 encryption.
Best practices
To enhance security in Harness AI SRE:
- Use RBAC policies to limit access.
- Enable OAuth/SAML authentication.
- Review audit logs regularly.
- Use API tokens with least privilege.
- Encrypt webhook notifications.
Next steps
- Go to AI SRE Security to review the full AI SRE permission reference and RBAC configuration.
- Go to Configure On-Call Teams and Routing to assign User Groups and service ownership.
- Go to Define Escalation Policies to control who is notified during an incident.