Skip to main content

Resource type reference

Last updated on

This topic lists resource types relevant to RBAC in Harness. Each resource type has an identifier used in APIs and YAML, and a permission key used to construct permission strings such as core_pipeline_view.


Resource types

Resource types are grouped by the Harness module or platform area that owns them. Platform resource types are available to every module, and module resource types require a license for that module.

Harness Platform

These resource types apply across Harness and are not specific to a single module.

IdentifierPermission key
ACCOUNTaccount
ORGANIZATIONorganization
PROJECTproject
CONNECTORconnector
DELEGATEdelegate
DELEGATECONFIGURATIONdelegateconfiguration
SECRETsecret
AUDITaudit
DASHBOARDSdashboards
TEMPLATEtemplate
TICKETticket
FILEfile
VARIABLEvariable
SMTPsmtp
SETTINGsetting
STREAMING_DESTINATIONstreamingDestination
MODULEmodule
GITX_WEBHOOKSgitxWebhooks
CERTIFICATEcertificate
PROVIDERprovider
RELEASESreleases
INPUT_SETinputset
BANNERbanner
OIDC_ID_TOKENoidcIdToken
DATA_SINKdataSink
AI_RULESrules
BRANDINGbranding
LLM_GATEWAYllmgateway
USERuser
SERVICEACCOUNTserviceaccount
USERGROUPusergroup
ROLErole
RESOURCEGROUPresourcegroup
LICENSElicense
AUTHSETTINGauthsetting
ACCESS_POLICIESaccessPolicies
NOTIFICATIONnotification
NOTIFICATION_CHANNELnotificationchannel
NOTIFICATION_RULEnotificationrule
DEFAULT_NOTIFICATION_TEMPLATE_SETdefaultNotificationTemplateSet
GOVERNANCEPOLICYgovernancePolicy
GOVERNANCEPOLICYSETSgovernancePolicySets
NETWORK_MAPnetworkmap

Continuous Delivery and GitOps

These resource types apply to pipelines, deployments, and GitOps.

IdentifierPermission key
PIPELINEpipeline
SERVICEservice
ENVIRONMENTenvironment
ENVIRONMENT_GROUPenvironmentgroup
GITOPS_AGENTagent
GITOPS_APPapplication
GITOPS_REPOSITORYrepository
GITOPS_CLUSTERcluster
GITOPS_GPGKEYgpgkey
GITOPS_CERTcert
GITOPS_APPLICATIONSETapplicationset
DEPLOYMENTFREEZEdeploymentfreeze

Code Repository

These resource types apply to Harness Code Repository.

IdentifierPermission key
CODE_REPOSITORYrepo

Artifact Registry

These resource types apply to Harness Artifact Registry.

IdentifierPermission key
ARTIFACT_REGISTRYartregistry
ARTIFACT_FIREWALL_EXCEPTIONSfirewallexceptions
HAR_REGISTRYharregistry

Security Testing Orchestration

These resource types apply to Harness STO.

IdentifierPermission key
STO_TESTTARGETtesttarget
STO_EXEMPTIONexemption
STO_ISSUEissue
STO_SCANscan
STO_OVERRIDEoverride

Supply Chain Security

These resource types apply to Harness SCS.

IdentifierPermission key
SSCA_REMEDIATION_TRACKERremediationtracker
SSCA_ENFORCEMENT_EXEMPTIONenforcementexemption

Feature Flags

These resource types apply to the Harness Feature Flags module.

IdentifierPermission key
FEATUREFLAGfeatureflag
FF_PROXYAPIKEYproxyapikey
TARGETtarget
TARGETGROUPtargetgroup

Feature Management and Experimentation

These resource types apply to Harness FME.

IdentifierPermission key
FME_ENVIRONMENTfmeenvironment
FME_TRAFFIC_TYPEfmetraffictype
FME_FEATURE_FLAGfmefeatureflag
FME_SEGMENTfmesegment
FME_LARGE_SEGMENTfmelargesegment
FME_METRICfmemetric
FME_EXPERIMENTfmeexperiment
FME_CONFIGfmeconfig
FME_AICONFIGfmeaiconfig

Cloud & AI Cost Management

These resource types apply to Harness CACM, including AutoStopping and Cloud Asset Governance.

IdentifierPermission key
CCM_OVERVIEWoverview
CCM_PERSPECTIVEperspective
CCM_FOLDERfolder
CCM_BUDGETbudget
CCM_COSTCATEGORYcostCategory
CCM_UNIT_COSTunitCost
CCM_AUTOSTOPPINGRULEautoStoppingRule
CCM_LOADBALANCERloadBalancer
CCM_CURRENCYPREFERENCEcurrencyPreference
CCM_CLOUD_ASSET_GOVERNANCE_RULEcloudAssetGovernanceRule
CCM_CLOUD_ASSET_GOVERNANCE_RULE_SETcloudAssetGovernanceRuleSet
CCM_CLOUD_ASSET_GOVERNANCE_RULE_ENFORCEMENTcloudAssetGovernanceEnforcement
CCM_CLOUD_ASSET_GOVERNANCE_OVERVIEWcloudAssetGovernanceOverview
CCM_CLOUD_ASSET_GOVERNANCE_ALERTcloudAssetGovernanceAlert
CCM_DATA_SCOPEdataScope
CCM_CLUSTER_ORCHESTRATORclusterOrchestrator
CCM_ANOMALIESanomalies
CCM_RECOMMENDATIONSrecommendations
CCM_COMMITMENT_ORCHESTRATORcommitmentOrchestrator
CCM_ANOMALIES_WHITELIST_RULEanomaliesWhitelistRule

Service Reliability Management

These resource types apply to Harness SRM.

IdentifierPermission key
MONITOREDSERVICEmonitoredservice
SLOslo
DOWNTIMEdowntime
MONITORING_AGENTmonitoringagent
METRIC_SOURCEmetricsource

Incident Response

These resource types apply to Harness Incident Response.

IdentifierPermission key
IRO_MANAGERiromanager
IRO_ALERTalert
IRO_ALERT_RULEalertrule
IRO_INCIDENTincident
IRO_CONNECT_WORKSPACEiroworkspace
IRO_RUNBOOKrunbook
IRO_SERVICE_DIRECTORYservicedirectory
IRO_THIRD_PARTY_INTEGRATIONSthirdpartyintegrations
IRO_ESCALATION_POLICYiroescalationpolicy
IRO_SCHEDULEiroschedule
IRO_SCHEDULE_OVERRIDEiroscheduleoverride

Resilience Testing

These resource types apply to Harness Resilience Testing.

IdentifierPermission key
CHAOS_HUBchaoshub
CHAOS_INFRASTRUCTUREchaosinfrastructure
CHAOS_EXPERIMENTchaosexperiment
CHAOS_GAMEDAYchaosgameday
CHAOS_PROBEchaosprobe
CHAOS_FAULTchaosfault
CHAOS_ACTIONchaosaction
CHAOS_IMAGE_REGISTRYchaosimageregistry
CHAOS_SECURITY_GOVERNANCEchaossecuritygovernance

Continuous Error Tracking

These resource types apply to Harness CET.

IdentifierPermission key
CET_AGENTagents
CET_TOKENtoken
CET_CRITICAL_EVENTcriticalevent

Internal Developer Portal

These resource types apply to Harness IDP.

IdentifierPermission key
IDP_CATALOGcatalog
IDP_ENVIRONMENTidpenvironment
IDP_ENVIRONMENT_BLUEPRINTenvironmentblueprint
IDP_WORKFLOWworkflow
IDP_PLUGINplugin
IDP_SCORECARDscorecard
IDP_LAYOUTlayout
IDP_CATALOG_ACCESS_POLICYcatalogaccesspolicy
IDP_INTEGRATIONintegration
IDP_ADVANCED_CONFIGURATIONadvancedconfiguration
IDP_AGGREGATION_RULEaggregationrule

Infrastructure as Code Management

These resource types apply to Harness IaCM.

IdentifierPermission key
IAC_WORKSPACEworkspace
IAC_REGISTRYregistry
IAC_PROVIDER_REGISTRYproviderregistry
IAC_VARIABLE_SETvariableset

AI DLC Insights and Software Engineering Insights

Every resource type in this group uses the SEI_ identifier prefix and the sei permission key prefix, because AI DLC Insights (AIDI) evolved from Software Engineering Insights (SEI). The prefix does not tell you which capability a resource type belongs to, so the following tables separate them.

Note that an identifier does not always match the label you see in the product. For example, SEI_CANVAS controls Studio.

AI DLC Insights

These resource types apply to Harness AIDI. Go to Harness RBAC for AI DLC Insights to review the scopes and out-of-the-box roles that use them.

IdentifierPermission keyProduct label
SEI_CANVASseicanvasStudio
SEI_INSIGHTS_CATEGORYseiinsightscategoryInsights Categories
SEI_TEAMSseiteamsTeams
SEI_DATA_SETTINGSseidatasettingsData Settings
SEI_DEVELOPERSseidevelopersData Settings, developer records
SEI_INTEGRATIONSseiintegrationsData Settings, integrations
SEI_PROFILESseiprofilesProfiles

Software Engineering Insights

These resource types apply to Harness SEI 1.0. Go to SEI roles and permissions to review the roles that use them.

IdentifierPermission keyProduct label
SEI_COLLECTIONSseicollectionsCollections
SEI_INSIGHTSseiinsightsInsights
SEI_CONFIGURATION_SETTINGSseiconfigurationsettingsConfiguration Settings

The SEI_PANORAMA (seipanorama) and SEI_GOALS (seigoals) resource types also exist in this namespace.

Database DevOps

These resource types apply to Harness Database DevOps.

IdentifierPermission key
DB_SCHEMAschema
DB_INSTANCEinstance

Cloud Development Environments

These resource types apply to Harness CDE Gitspaces.

IdentifierPermission key
CDE_GITSPACEgitspace
CDE_INFRAPROVIDERinfraprovider