> For the complete documentation index, see [llms.txt](https://developer.harness.io/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://developer.harness.io/infrastructure-as-code-management/platform/workspaces/workspace-rbac.md).

# Workspace Permissions

Configure role-based access control for IaCM workspaces and variables.

You can control who has different types of access to the Workspace in a project. Create/edit a Role, and select the "Infrastructure as Code Management" section

![Resources](https://3575326923-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2Ffhx6XzjvtJmfv5gPWZ5m%2Fuploads%2Fgit-blob-02a899cc302ce376f3dbb42a24929195e0964571%2Fworkspace-rbac.png?alt=media)

For each Role, you can define the following set of permissions:

1. **View** - Permitting users to view the Workspaces in the project
2. **Create/Edit** - Permitting users to create and edit Workspaces in the project
3. **Delete** - Permitting users to delete Workspaces in the project
4. **Edit Variables** - Permitting users to create and edit Environment and Terraform variables
5. **Delete Variables** - Permitting users to delete Environment and Terraform variables
6. **Approve** - Permitting users to approve the Infrastructure Stage (using the approval step)
7. **Access State** - Permitting users to view the state (including historical revisions)

## Using Resource Groups <a href="#using-resource-groups" id="using-resource-groups"></a>

You can utilize Resource Groups functionality to specify which users can access a specific Workspace. For this, create a resource group, add the specific (or all) Workspaces, and bind it to a specific user or user group.

![Resources](https://3575326923-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2Ffhx6XzjvtJmfv5gPWZ5m%2Fuploads%2Fgit-blob-375c2a921a72e961607de38f697f1965bd817a43%2Fworkspace-rg.png?alt=media)

To learn more about Resource Groups, go to [this documentation](/harness-ai/use-harness-platform/platform-access-control/manage-resource-groups.md)

{% @harness-feedback/feedback %}
