Permissions Reference
This topic gives you details of the Harness Permissions and Default Roles and Resource Groups available in the Harness system.
Default Roles
Each Harness Account, Organization and Project includes default Roles to help you with RBAC.
The following table lists permissions corresponding to the default roles at the Account scope:
Role | Resource Type | Permissions |
Account Admin | Resource Groups | |
Service Accounts | ||
Organizations | ||
Roles | ||
Account Settings | ||
Projects | ||
Users | ||
Authentication Settings | ||
User Groups | ||
Governance Policy Sets | ||
Variables | ||
Templates | ||
Governance Policies | ||
Dashboards | ||
Delegate Configurations | ||
Delegates | ||
Secrets | ||
Connectors | ||
Environments | ||
ChaosHub | ||
Clusters | ||
Agents | ||
Repository Certificates | ||
Applications | ||
Repositories | ||
GnuPG Keys | ||
Environment Groups | ||
SLO | ||
Monitored Services | ||
Pipelines | ||
Services | ||
Feature Flags | ||
Target Management | ||
Account Viewer | Resource Groups | |
Service Accounts | ||
Organizations | ||
Roles | ||
Account Settings | ||
Projects | ||
Users | ||
Authentication Settings | ||
User Groups | ||
Governance Policy Sets | ||
Variables | ||
Templates | ||
Governance Policies | ||
Dashboards | ||
Delegate Configurations | ||
Delegates | ||
Secrets | ||
Connectors | ||
Environments | ||
ChaosHub | ||
Clusters | ||
Agents | ||
Repository Certificates | ||
Applications | ||
Repositories | ||
GnuPG Keys | ||
Environment Groups | ||
SLO | ||
Monitored Services | ||
Pipelines | ||
Services | ||
GitOps Admin Role | Clusters | |
Agents | ||
Repository Certificates | ||
Applications | ||
Repositories | ||
GnuPG Keys | ||
Feature Flag Manage Role | Feature Flags | |
Target Management | ||
The following table lists permissions corresponding to the default roles at the Organization scope:
Role | Resource Type | Permissions |
Organization Admin | Resource Groups | |
Service Accounts | ||
Organizations | ||
Roles | ||
Projects | ||
Users | ||
User Groups | ||
Governance Policy Sets | ||
Variables | ||
Templates | ||
Governance Policies | ||
Dashboards | ||
Delegate Configurations | ||
Delegates | ||
Secrets | ||
Connectors | ||
Environments | ||
ChaosHub | ||
Clusters | ||
Agents | ||
Repository Certificates | ||
Applications | ||
Repositories | ||
GnuPG Keys | ||
Environment Groups | ||
SLO | ||
Monitored Services | ||
Pipelines | ||
Services | ||
Feature Flags | ||
Target Management | ||
Organization Viewer | Resource Groups | |
Service Accounts | ||
Organizations | ||
Roles | ||
Projects | ||
Users | ||
User Groups | ||
Governance Policy Sets | ||
Variables | ||
Templates | ||
Governance Policies | ||
Dashboards | ||
Delegate Configurations | ||
Delegates | ||
Secrets | ||
Connectors | ||
Environments | ||
ChaosHub | ||
Clusters | ||
Agents | ||
Repository Certificates | ||
Applications | ||
Repositories | ||
GnuPG Keys | ||
Environment Groups | ||
SLO | ||
Monitored Services | ||
Pipelines | ||
Services | ||
GitOps Admin Role | Clusters | |
Agents | ||
Repository Certificates | ||
Applications | ||
Repositories | ||
GnuPG Keys | ||
Feature Flag Manage Role | Feature Flags | |
Target Management | ||
The following table lists permissions corresponding to the default roles at the Project scope:
Role | Resource Type | Permissions |
Pipeline Executor | Resource Groups | |
Roles | ||
Projects | ||
Users | ||
User Groups | ||
Variables | ||
Templates | ||
Secrets | ||
Connectors | ||
Environments | ||
Environment Groups | ||
Pipelines | ||
Services | ||
Project Admin | Resource Groups | |
Service Accounts | ||
Roles | ||
Projects | ||
Users | ||
User Groups | ||
Governance Policy Sets | ||
Variables | ||
Templates | ||
Governance Policies | ||
Delegate Configurations | ||
Delegates | ||
Dashboards | ||
Delegate Configurations | ||
Delegates | ||
Secrets | ||
Connectors | ||
Environments | ||
ChaosHub | ||
Clusters | ||
Agents | ||
Repository Certificates | ||
Applications | ||
Repositories | ||
GnuPG Keys | ||
Environment Groups | ||
SLO | ||
Monitored Services | ||
Pipelines | ||
Services | ||
Feature Flags | ||
Target Management | ||
Project Viewer | Resource Groups | |
Service Accounts | ||
Roles | ||
Projects | ||
Users | ||
User Groups | ||
Governance Policy Sets | ||
Variables | ||
Templates | ||
Governance Policies | ||
Delegate Configurations | ||
Delegates | ||
Dashboards | ||
Delegate Configurations | ||
Delegates | ||
Secrets | ||
Connectors | ||
Environments | ||
ChaosHub | ||
Clusters | ||
Agents | ||
Repository Certificates | ||
Applications | ||
Repositories | ||
GnuPG Keys | ||
Environment Groups | ||
SLO | ||
Monitored Services | ||
Pipelines | ||
Services | ||
GitOps Admin Role | Clusters | |
Agents | ||
Repository Certificates | ||
Applications | ||
Repositories | ||
GnuPG Keys | ||
Feature Flag Manage Role | Feature Flags | |
Target Management | ||
Default Resource Group
Harness includes the following default Resource Groups at the Account, Org, and Project scope:
Scope | Resource Group | Description |
Account | All Resources Including Child Scopes | Includes all the resources within the scope of the Account, as well as those within the scope of the Orgs and Projects in this Account. |
Account | All Account Level Resources | Includes all the resources within the scope of the Account. This does not include resources within the scope of Org or Project. |
Org | All Resources Including Child Scopes | Includes all the resources within the scope of the Org, as well as those within the scope of all the Projects created within this Org. |
Org | All Organization Level Resources | Includes all the resources within the scope of the Org. This does not include resources within the scope of Projects. |
Project | All Project Level Resources | Includes all the resources within the scope of the Project. |