> For the complete documentation index, see [llms.txt](https://developer.harness.io/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://developer.harness.io/service-reliability-management/troubleshooting-and-resources/srm-roles-and-permissions.md).

# Access Control

Harness employs Role-Based Access Control (RBAC) to manage user and group access to Harness resources based on their roles. RBAC enhances security and operational efficiency.

The Harness Platform has a three-level hierarchical structure. The three levels, or scopes, are Account, Organization (Org), and Project. An Account contains Organizations and Projects. An Organization contains Projects.

To learn more about access control in Harness, go to [RBAC in Harness](/harness-ai/use-harness-platform/platform-access-control.md).

This section describes the permissions available for Service Reliability Management (SRM).

## SRM specific permissions <a href="#srm-specific-permissions" id="srm-specific-permissions"></a>

You can assign the following SRM specific permissions to roles in Harness:

* View SLO
* Create/edit SLO
* Delete SLO
* View monitored services
* Create/edit monitored services
* Delete monitored services
* Toggle monitored services
* View downtime
* Create/edit downtime
* Delete downtime

## Harness Platform roles and SRM permissions <a href="#harness-platform-roles-and-srm-permissions" id="harness-platform-roles-and-srm-permissions"></a>

The following default Harness Platform roles come with specific SRM permissions:

### Account Admin role <a href="#account-admin-role" id="account-admin-role"></a>

The **Account Admin** role includes the following SRM specific permissions:

* View SLO
* Create/edit SLO
* Delete SLO
* View monitored services
* Create/edit monitored services
* Delete monitored services
* Toggle monitored services
* View downtime
* Create/edit downtime
* Delete downtime

### Account Viewer role <a href="#account-viewer-role" id="account-viewer-role"></a>

The **Account Viewer** role includes the following SRM specific permissions:

* View SLO
* View monitored services
* View downtime

### Org Admin role <a href="#org-admin-role" id="org-admin-role"></a>

The **Org Admin** role includes the following SRM specific permissions:

* View SLO
* Create/edit SLO
* Delete SLO
* View monitored services
* Create/edit monitored services
* Delete monitored services
* Toggle monitored services
* View downtime
* Create/edit downtime
* Delete downtime

### Org Viewer role <a href="#org-viewer-role" id="org-viewer-role"></a>

The **Org Viewer** role includes the following SRM specific permissions:

* View SLO
* View monitored services
* View downtime

### Project Admin role <a href="#project-admin-role" id="project-admin-role"></a>

The **Project Admin** role includes the following SRM specific permissions:

* View SLO
* Create/edit SLO
* Delete SLO
* View monitored services
* Create/edit monitored services
* Delete monitored services
* Toggle monitored services
* View downtime
* Create/edit downtime
* Delete downtime

### Project Viewer role <a href="#project-viewer-role" id="project-viewer-role"></a>

The **Project Viewer** role includes the following SRM specific permissions:

* View SLO
* View monitored services
* View downtime

## See also <a href="#see-also" id="see-also"></a>

The following topics can help you understand how to implement access control in Harness:

* [Manage users](/harness-ai/use-harness-platform/platform-access-control/add-users.md)
* [Manage user groups](/harness-ai/use-harness-platform/platform-access-control/add-user-groups.md)
* [Manage resource groups](/harness-ai/use-harness-platform/platform-access-control/manage-resource-groups.md)
* [Manage roles](/harness-ai/use-harness-platform/platform-access-control/add-manage-roles.md)

FEEDBACK\_BUTTON
