Permissions reference
Introducing a new set of permissions, while marking existing DEPRECATED permissions as INACTIVE.
Currently, Notification Rules and Notification Channels are governed by a single set of permissions:
| Resource | Permissions | Current status | New status |
|---|---|---|---|
| Notifications Rules and Notification Channels | core_notification_view)core_notification_edit)core_notification_delete) | DEPRECATED | INACTIVE |
However, starting from June 12, 2025, these permissions will become non-operational. They will be replaced with separate new permissions:
| Resource | New Permissions | Current status | New status |
|---|---|---|---|
| Notification Rules | core_notificationrule_view)core_notificationrule_edit)core_notificationrule_delete) | EXPERIMENTAL | ACTIVE |
| Notification Channels | core_notificationchannel_view)core_notificationchannel_edit)core_notificationchannel_delete) | EXPERIMENTAL | ACTIVE |
If any automation relies on these core_notification_view/edit/delete permissions, we recommend updating them accordingly.
Note: The existing legacy notification permissions are DEPRECATED and will soon be moved to an INACTIVE state. The new permissions will be released in the ACTIVE state with RBAC enforced.
This topic describes permissions relevant to RBAC in Harness. For API permissions, go to the API permissions reference.
Types of Permission:
| Status | Description |
|---|---|
| EXPERIMENTAL | Available for role assignment but RBAC will not be enforced, that is the access checks always return true. |
| ACTIVE | Available for role assignment with RBAC enforced. |
| DEPRECATED | Available for role assignment with RBAC enforced but the permission will be moved to the INACTIVE state after some time. |
| INACTIVE | No longer supported and access checks always return true. |
Administrative Functions
| Resource | Permissions | Status |
|---|---|---|
| Resource Groups |
| Active |
| Account Settings | Available at the account scope only.
| Active |
| Default Settings |
| Active |
| Projects |
| Active |
| User Groups |
| Active |
| Service Accounts |
| Active |
| Organizations | Available at the account and org scopes only.
| Active |
| Roles |
| Active |
| Streaming Destination | Available at the account scope only.
| Experimental |
| Banners | Available at the account scope only.
| Active |
| Users |
| Active |
| Authentication Settings | Available at the account scope only.
| Active |
| SMTP Configuration |
| Active |
| Certificates |
| Active |
| Account Management |
| Active |
| Licenses |
| Active |
| Audit |
| Active |
| Deployment Freezes |
| Active |
| Providers |
| Experimental |
Monitoring
| Resource | Permissions | Status |
|---|---|---|
| Monitoring Agents |
| Experimental |
| Service Level Objectives |
| Experimental |
Environment Groups
| Resource | Permissions | Status |
|---|---|---|
| Environment Groups |
| Active |
Environments
| Resource | Permissions | Status |
|---|---|---|
| Environments |
| Active |
Pipelines
| Resource | Permissions | Status |
|---|---|---|
| Pipelines |
| Active |
Services
| Resource | Permissions | Status |
|---|---|---|
| Services |
| Active |
Shared Resources
| Resource | Permissions | Status |
|---|---|---|
| Templates |
| Active |
| Deployment Freeze |
| Active |
| Secrets |
| Active |
| Connectors |
| Active |
| Variables |
| Active |
| Files |
| Active |
| Dashboards |
| Active |
| Delegate Configurations |
| Active |
| Delegates |
| Active |
Policies
| Resource | Permissions | Status |
|---|---|---|
| Governance Policies |
| Active |
| Governance Policy Sets |
| Active |
Discovery
| Resource | Permissions | Status |
|---|---|---|
| Network Map |
| Active |
Supply Chain Security
| Resource | Permissions | Status |
|---|---|---|
| Remediation Tracker |
| Active |
Webhooks
| Resource | Permissions | Status |
|---|---|---|
| Webhooks |
| Active |
Notifications
| Resource | Permissions | Status |
|---|---|---|
| Notification Rules |
| EXPERIMENTAL |
| Notification Channels |
| EXPERIMENTAL |
| Legacy Notifications |
| DEPRECATED |
Input Sets
| Resource | Permissions | Status |
|---|---|---|
| Input Sets |
| Active |
Module-specific permissions
Chaos Engineering
| Resource | Permissions | Status |
|---|---|---|
| Chaos Infrastructure |
| Active |
| Chaos Gameday |
| Active |
| Chaos Hub |
| Active |
| Chaos Experiment |
| Active |
| Chaos Probe |
| Active |
| Chaos Security Governance |
| Active |
| Chaos Image Registry |
| Active |
Cloud Cost Management
| Resource | Permissions | Status |
|---|---|---|
| Currency Preferences |
| Active |
| Overview |
| Active |
| Cost Categories |
| Active |
| Folders |
| Active |
| Perspectives |
| Active |
| AutoStopping Rules |
| Active |
| Budgets |
| Active |
| Load Balancer |
| Active |
| Data Scope |
| Active |
| Anomalies |
| Active |
| Recommendations |
| Active |
| Commitment Orchestrator |
| Active |
| Cluster Orchestrator |
| Experimental |
| Cloud Asset Governance Rule |
| Active |
| Cloud Asset Governance Rule Set |
| Active |
| Cloud Asset Governance Enforcement |
| Active |
Code Repository
| Resource | Permissions | Status |
|---|---|---|
| Repository |
| Active |
Feature Flags
| Resource | Permissions | Status |
|---|---|---|
| Feature flags |
| Active |
| Target Management |
| Active |
| Feature Flag |
| Active |
| Target |
| Active |
| Environment |
| Active |
| Proxy API Keys |
| Active |
GitOps
| Resource | Permissions | Status |
|---|---|---|
| Clusters |
| Active |
| Agents |
| Active |
| GnuPG Keys |
| Active |
| Repository Certificates |
| Active |
| Applications |
| Active |
| Application Sets |
| Experimental |
| Repositories |
| Active |
| Certificates |
| Active |
Infrastructure as Code
| Resource | Permissions | Status |
|---|---|---|
| IACM Workspaces |
| Active |
| Registry |
| Active |
| Variable Sets |
| Experimental |
Service Reliability
| Resource | Permissions | Status |
|---|---|---|
| SLO |
| Active |
| Monitored Services |
| Active |
| Downtime |
| Active |
Security Tests
| Resource | Permissions | Status |
|---|---|---|
| Issues |
| Active |
| Scans |
| Active |
| Test Targets |
| Active |
| Exemptions |
| Active |
| External Tickets |
| Active |
Internal Developer Portal
| Resource | Permissions | Status |
|---|---|---|
| Plugins |
| Active |
| Scorecards |
| Active |
| Layouts |
| Active |
| Catalog Access Policies |
| Active |
| Integrations |
| Active |
| Advanced Configurations |
| Active |
| Catalog |
| Active |
| Workflow |
| Active |
Continuous Error Tracking
| Resource | Permissions | Status |
|---|---|---|
| Tokens |
| Active |
| Critical Events |
| Active |
| Agents |
| Active |
Database DevOps
| Resource | Permissions | Status |
|---|---|---|
| Schemas |
| Active |
| Instances |
| Active |
Artifact Management
| Resource | Permissions | Status |
|---|---|---|
| Artifact Registry |
| Active |
Software Engineering Insights
| Resource | Permissions | Status |
|---|---|---|
| SEI Collections |
| Active |
| SEI Configuration Settings |
| Active |
| SEI Insights |
| Active |
Feature Management and Experimentation
| Resource | Permissions | Status |
|---|---|---|
| FME Environment |
| Active |
| FME Feature Flag |
| Active |
| FME Experiment |
| Active |
| FME Segment |
| Active |
| FME Large Segment |
| Active |
| FME Metric |
| Active |
| FME Traffic Type |
| Active |