Access
Organization roles, published plugin shares, and the Cloud audit log.
HarnessTap Cloud uses role-based access at the organization level. Published plugin visibility and cross-org shares add a second layer for bundle-level access.
Cloud does not ship apm-policy.yml. CLI ht audit scans project files for hidden Unicode, lockfile hashes, and optional apm-policy.yml. That is separate from the Cloud audit log below.
Organization roles
| Role | Typical permissions |
|---|---|
| Owner | Full control including billing, ownership transfer, and member management |
| Admin | Invite members, manage published plugins, configure org settings (billing varies by plan) |
| Member | Use published plugins, publish where permitted, accept invitations |
Exact publish and invite permissions may vary by plan. Admins and owners manage membership from /organizations/[slug].
Visibility and shares
- Organization-scoped — visible only to org members
- Shared — granted to other organizations via plugin shares with
readorforkaccess - Public — listed in the open catalog
Cross-org shares let partners consume approved bundles without joining your organization.
Audit log
HarnessTap Cloud maintains an append-only audit log scoped to each organization. Administrative actions — invitations, role changes, visibility updates, and publishes — are recorded for compliance review. This is a Cloud product log, not a CLI audit command.
Audit log depth and export options expand on Enterprise plans.
Related
- Audit — CLI Unicode / lock hash /
apm-policy.ymlscanner - Organizations
- Published plugins