Permissions reference
Last updated on
This topic describes permissions relevant to RBAC in Harness. For API permissions, go to the API permissions reference.
Types of permission
Types of permission:
| Status | Description |
|---|---|
| EXPERIMENTAL | Available for role assignment but RBAC will not be enforced, that is the access checks always return true. |
| ACTIVE | Available for role assignment with RBAC enforced. |
| DEPRECATED | Available for role assignment with RBAC enforced but the permission will be moved to the INACTIVE state after some time. |
This reference lists permissions that are available for role assignment. The Status column shows a resource's primary status; when an individual permission has a different status, it is annotated inline after its identifier (for example, gitops_application_exec, Experimental).
Administrative Functions
| Resource | Permissions | Status |
|---|---|---|
| Access Policies |
| Active |
| Account Management | Available at the account scope only.
| Active |
| Account Settings |
| Active |
| Audit | Available at the account and org scopes only.
| Active |
| Authentication Settings | Available at the account scope only.
| Active |
| Banners | Available at the account scope only.
| Active |
| Branding | Available at the account scope only.
| Active |
| Certificates |
| Active |
| Data Sink | Available at the account scope only.
| Active |
| Delegate Transaction Queue |
| Active |
| Deployment Freeze |
| Active |
| Licenses | Available at the account scope only.
| Active |
| OIDC ID Token |
| Active |
| Organizations | Available at the account and org scopes only.
| Active |
| Platform Alert Settings | Available at the account scope only.
| Active |
| Projects |
| Active |
| Providers | Available at the account scope only.
| Active |
| Resource Groups |
| Active |
| Roles |
| Active |
| SMTP Configuration | Available at the account scope only.
| Active |
| Service Accounts |
| Active |
| Streaming Destination | Available at the account scope only.
| Active |
| User Groups |
| Active |
| Users |
| Active |
Monitoring
| Resource | Permissions | Status |
|---|---|---|
| Monitoring Agents |
| Experimental |
| Service Level Objectives |
| Active |
Environment Groups
| Resource | Permissions | Status |
|---|---|---|
| Environment Groups |
| Active |
Environments
| Resource | Permissions | Status |
|---|---|---|
| Environments |
| Active |
Pipelines
| Resource | Permissions | Status |
|---|---|---|
| Pipelines |
| Active |
| Releases |
| Active |
Services
| Resource | Permissions | Status |
|---|---|---|
| Services |
| Active |
Shared Resources
| Resource | Permissions | Status |
|---|---|---|
| Connectors |
| Active |
| Dashboards | Available at the account and org scopes only.
| Active |
| Delegate Configurations |
| Active |
| Delegates |
| Active |
| Files |
| Active |
| Secrets |
| Active |
| Templates |
| Active |
| Variables |
| Active |
Policies
| Resource | Permissions | Status |
|---|---|---|
| Governance Policies |
| Active |
| Governance Policy Sets |
| Active |
Discovery
| Resource | Permissions | Status |
|---|---|---|
| Network Map |
| Active |
Supply Chain Security
| Resource | Permissions | Status |
|---|---|---|
| Remediation Tracker |
| Active |
| SCS Configuration |
| Active |
| SCS Evidence Vault |
| Active |
| SCS External Ticket |
| Active |
| SCS Integration |
| Active |
| SCS Pull Request |
| Active |
Webhooks
| Resource | Permissions | Status |
|---|---|---|
| Webhooks |
| Active |
Notifications
| Resource | Permissions | Status |
|---|---|---|
| Default Notification Template Set |
| Active |
| Legacy Notifications |
| Deprecated |
| Notification Channels |
| Active |
| Notification Rules |
| Active |
Input Sets
| Resource | Permissions | Status |
|---|---|---|
| Input Sets |
| Active |
Module-specific permissions
Chaos Engineering
| Resource | Permissions | Status |
|---|---|---|
| Chaos Action |
| Active |
| Chaos Environment |
| Active |
| Chaos Experiment |
| Active |
| Chaos Fault |
| Active |
| Chaos Gameday |
| Active |
| Chaos Hub |
| Active |
| Chaos Image Registry |
| Active |
| Chaos Infrastructure |
| Active |
| Chaos Probe |
| Active |
| Chaos Security Governance |
| Active |
| DR Test |
| Experimental |
Cloud Cost Management
| Resource | Permissions | Status |
|---|---|---|
| Anomalies | Available at the account scope only.
| Active |
| Anomalies Ignore List Rules | Available at the account scope only.
| Active |
| AutoStopping Rules | Available at the account scope only.
| Active |
| Budgets | Available at the account scope only.
| Active |
| Cloud Asset Governance Alert | Available at the account scope only.
| Active |
| Cloud Asset Governance Enforcement | Available at the account scope only.
| Active |
| Cloud Asset Governance Overview | Available at the account scope only.
| Active |
| Cloud Asset Governance Rule | Available at the account scope only.
| Active |
| Cloud Asset Governance Rule Set | Available at the account scope only.
| Active |
| Cluster Orchestrator | Available at the account scope only.
| Active |
| Commitment Orchestrator | Available at the account scope only.
| Active |
| Cost Categories | Available at the account scope only.
| Active |
| Currency Preferences | Available at the account scope only.
| Active |
| Data Job Status | Available at the account scope only.
| Active |
| Data Scope | Available at the account scope only.
| Active |
| Folders | Available at the account scope only.
| Active |
| Load Balancer | Available at the account scope only.
| Active |
| Overview | Available at the account scope only.
| Active |
| Perspectives | Available at the account scope only.
| Active |
| Recommendations | Available at the account scope only.
| Active |
| Unit Cost | Available at the account scope only.
| Active |
Cloud Development Environments
| Resource | Permissions | Status |
|---|---|---|
| Gitspace |
| Experimental |
| Infrastructure Provider |
| Experimental |
Code Repository
| Resource | Permissions | Status |
|---|---|---|
| Repository |
| Active |
Feature Flags
| Resource | Permissions | Status |
|---|---|---|
| Environment |
| Active |
| Feature Flag |
| Active |
| Proxy API Keys | Available at the account and org scopes only.
| Active |
| Target |
| Active |
| Target Management |
| Active |
GitOps
| Resource | Permissions | Status |
|---|---|---|
| Agents |
| Active |
| Application Sets |
| Active |
| Applications |
| Active |
| Argo Project |
| Active |
| Certificates |
| Active |
| Clusters |
| Active |
| Repositories |
| Active |
| Repository Certificates |
| Active |
Infrastructure as Code
| Resource | Permissions | Status |
|---|---|---|
| IACM Inventory |
| Active |
| IACM Playbook |
| Active |
| IACM Provider Registry |
| Experimental |
| IACM Workspaces |
| Active |
| Registry |
| Active |
| Variable Sets |
| Experimental |
Service Reliability
| Resource | Permissions | Status |
|---|---|---|
| Downtime |
| Active |
| Monitored Services |
| Active |
| SLO |
| Active |
Incident Response
| Resource | Permissions | Status |
|---|---|---|
| Alert |
| Active |
| Alert Rule |
| Active |
| Escalation Policy |
| Active |
| Incident |
| Active |
| Incident Response Access |
| Active |
| Incident Response Integration |
| Active |
| Incident Response Workspace |
| Active |
| Metric Source |
| Active |
| On-Call Schedule |
| Active |
| On-Call Schedule Override |
| Active |
| Runbook |
| Active |
| Service Directory |
| Experimental |
| Third-Party Integrations |
| Experimental |
Security Tests
| Resource | Permissions | Status |
|---|---|---|
| Exemptions |
| Active |
| External Tickets |
| Active |
| Issues |
| Active |
| Scans |
| Active |
| Test Targets |
| Active |
Internal Developer Portal
| Resource | Permissions | Status |
|---|---|---|
| Advanced Configurations |
| Active |
| Aggregation Rule |
| Active |
| Catalog |
| Active |
| Catalog Access Policies |
| Active |
| Environment Blueprint |
| Active |
| IDP Environment |
| Active |
| IDP Module |
| Active |
| IDP Team |
| Active |
| Integrations |
| Active |
| Layouts |
| Active |
| Plugins |
| Active |
| Scorecards |
| Active |
| Workflow |
| Active |
Continuous Error Tracking
| Resource | Permissions | Status |
|---|---|---|
| Agents |
| Active |
| Critical Events |
| Active |
| Tokens |
| Active |
Database DevOps
| Resource | Permissions | Status |
|---|---|---|
| Instances |
| Active |
| Schemas |
| Active |
Artifact Management
| Resource | Permissions | Status |
|---|---|---|
| Artifact Registry |
| Active |
| Firewall Exceptions |
| Active |
AI
| Resource | Permissions | Status |
|---|---|---|
| AI LLM Gateway |
| Active |
| AI Rules |
| Active |
| AI Worker Agent |
| Active |
AI DLC Insights
| Resource | Permissions | Status |
|---|---|---|
| AIDI Collections |
| Active |
| AIDI Configuration Settings | Available at the account scope only.
| Active |
| AIDI Data Settings | Available at the account scope only.
| Active |
| AIDI Insight Categories |
| Active |
| AIDI Insights |
| Active |
| AIDI Profiles | Available at the account scope only.
| Active |
| AIDI Studio |
| Active |
| AIDI Teams |
| Active |
Feature Management and Experimentation
| Resource | Permissions | Status |
|---|---|---|
| FME Environment |
| Active |
| FME Experiment |
| Active |
| FME Feature Flag |
| Active |
| FME Metric |
| Active |
| FME Segment |
| Active |
| FME Traffic Type |
| Active |
Load Testing
| Resource | Permissions | Status |
|---|---|---|
| Load Test |
| Active |