Cloud

Access

Organization roles, published plugin shares, and the Cloud audit log.

HarnessTap Cloud uses role-based access at the organization level. Published plugin visibility and cross-org shares add a second layer for bundle-level access.

Cloud does not ship apm-policy.yml. CLI ht audit scans project files for hidden Unicode, lockfile hashes, and optional apm-policy.yml. That is separate from the Cloud audit log below.

Organization roles

RoleTypical permissions
OwnerFull control including billing, ownership transfer, and member management
AdminInvite members, manage published plugins, configure org settings (billing varies by plan)
MemberUse published plugins, publish where permitted, accept invitations

Exact publish and invite permissions may vary by plan. Admins and owners manage membership from /organizations/[slug].

Visibility and shares

  • Organization-scoped — visible only to org members
  • Shared — granted to other organizations via plugin shares with read or fork access
  • Public — listed in the open catalog

Cross-org shares let partners consume approved bundles without joining your organization.

Audit log

HarnessTap Cloud maintains an append-only audit log scoped to each organization. Administrative actions — invitations, role changes, visibility updates, and publishes — are recorded for compliance review. This is a Cloud product log, not a CLI audit command.

Audit log depth and export options expand on Enterprise plans.