Access
Roles, permissions, published layer shares, and audit logging.
Access control
HarnessTap Cloud uses role-based access control (RBAC) at the organization level. Published layer visibility and cross-org shares add a second layer for bundle-level access.
Organization roles
| Role | Typical permissions |
|---|---|
| Owner | Full control including billing, ownership transfer, and member management |
| Admin | Invite members, manage published layers, configure org settings (billing varies by plan) |
| Member | Use published layers, publish where permitted, accept invitations |
Exact publish and invite permissions may vary by plan tier. Admins and owners can manage membership from /organizations/[slug].
Published layer visibility and shares
Beyond org membership, published layers can be:
- Organization-scoped — visible only to org members
- Shared — granted to other organizations via
published_layer_shareswithreadorforkaccess - Public — listed in the open catalog
Cross-org shares let partners consume your approved bundles without joining your organization.
Audit log
HarnessTap Cloud maintains an append-only audit log scoped to each organization. Administrative actions — invitations, role changes, visibility updates, and publishes — are recorded for compliance review.
Audit log depth and export options expand on Enterprise plans.
Related guides
- Organizations — invitations and domain routing
- Published layers — visibility and publish workflow