> For the complete documentation index, see [llms.txt](https://developer.harness.io/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://developer.harness.io/continuous-error-tracking/cet-roles-and-permissions.md).

# Access Control

Harness employs Role-Based Access Control (RBAC) to manage user and group access to Harness resources based on their roles. RBAC enhances security and operational efficiency.

The Harness Platform has a three-level hierarchical structure. The three levels, or scopes, are Account, Organization (Org), and Project. An Account contains Organizations and Projects. An Organization contains Projects.

To learn more about access control in Harness, go to [RBAC in Harness](/harness-ai/use-harness-platform/platform-access-control.md).

This section describes the roles available for Continuous Error Tracking (CET).

### CET-specific role <a href="#cet-specific-role" id="cet-specific-role"></a>

The **CET Admin** default role is available specifically for CET at the Account, Organization (Org), and Project levels. The **CET Admin** role includes the following permissions:

* View tokens
* Create/edit tokens
* Revoke tokens
* View critical events
* Create/edit critical events
* Delete critical events
* View Agents

### Harness Platform roles and CET permissions <a href="#harness-platform-roles-and-cet-permissions" id="harness-platform-roles-and-cet-permissions"></a>

The following default Harness Platform roles come with specific CET permissions:

### Account Admin role <a href="#account-admin-role" id="account-admin-role"></a>

The **Account Admin** role includes the following CET specific permissions:

* View tokens
* Create/edit tokens
* Revoke tokens
* View critical events
* Create/edit critical events
* Delete critical events
* View Agents

### Account Viewer role <a href="#account-viewer-role" id="account-viewer-role"></a>

The **Account Viewer** role includes the following CET specific permissions:

* View tokens
* View critical events
* View Agents

### Org Admin role <a href="#org-admin-role" id="org-admin-role"></a>

The **Org Admin** role includes the following CET specific permissions:

* View tokens
* Create/edit tokens
* Revoke tokens
* View critical events
* Create/edit critical events
* Delete critical events
* View Agents

### Org Viewer role <a href="#org-viewer-role" id="org-viewer-role"></a>

The **Org Viewer** role includes the following CET specific permissions:

* View tokens
* View critical events
* View Agents

### Project Admin role <a href="#project-admin-role" id="project-admin-role"></a>

The **Project Admin** role includes the following CET specific permissions:

* View tokens
* Create/edit tokens
* Revoke tokens
* View critical events
* Create/edit critical events
* Delete critical events
* View Agents

### Project Viewer role <a href="#project-viewer-role" id="project-viewer-role"></a>

The **Project Viewer** role includes the following CET specific permissions:

* View tokens
* View critical events
* View Agents

### Related concepts <a href="#see-also" id="see-also"></a>

The following topics can help you understand how to implement access control in Harness:

* [Manage users](/harness-ai/use-harness-platform/platform-access-control/add-users.md)
* [Manage user groups](/harness-ai/use-harness-platform/platform-access-control/add-user-groups.md)
* [Manage resource groups](/harness-ai/use-harness-platform/platform-access-control/manage-resource-groups.md)
* [Manage roles](/harness-ai/use-harness-platform/platform-access-control/add-manage-roles.md)
