Cloud

Access

Roles, permissions, published layer shares, and audit logging.

Access control

HarnessTap Cloud uses role-based access control (RBAC) at the organization level. Published layer visibility and cross-org shares add a second layer for bundle-level access.

Organization roles

RoleTypical permissions
OwnerFull control including billing, ownership transfer, and member management
AdminInvite members, manage published layers, configure org settings (billing varies by plan)
MemberUse published layers, publish where permitted, accept invitations

Exact publish and invite permissions may vary by plan tier. Admins and owners can manage membership from /organizations/[slug].

Published layer visibility and shares

Beyond org membership, published layers can be:

  • Organization-scoped — visible only to org members
  • Shared — granted to other organizations via published_layer_shares with read or fork access
  • Public — listed in the open catalog

Cross-org shares let partners consume your approved bundles without joining your organization.

Audit log

HarnessTap Cloud maintains an append-only audit log scoped to each organization. Administrative actions — invitations, role changes, visibility updates, and publishes — are recorded for compliance review.

Audit log depth and export options expand on Enterprise plans.