In this article: Learn how to control who can access specific projects and what they can do within them. This guide covers Ontario-level and project-level roles, the different paths for adding members, how Harness file and folder access connects to project roles, and best practices for managing your team across the platform.
Â
Overview
Project membership controls who can access and collaborate within specific Ontario projects. Each project maintains its own team with assigned roles that determine what each person can see and do within that project. Project-level roles are independent of a user's Ontario-level role, giving you precise control over access at every tier.
There are two paths for adding users to projects, and they are not interchangeable. The Ontario landing page is where your Ontario Admin manages the full picture: creating users, assigning Ontario-level roles, adding them to groups, and enrolling them in one or more projects simultaneously. The project itself also allows a Project Admin to add users directly—including brand new users who don't yet exist in Ontario—but this path is intentionally limited in scope. Choosing the right starting point depends on the user's role across your environment.
Recommended workflow: Whenever possible, have your Ontario Admin create and manage users from the Ontario-level Users tab. This ensures users are properly set up across the environment, assigned the right Ontario role, and added to all the projects they need—in a single step.
Understanding the Role System
Ontario uses two independent role tiers. Understanding both is essential before adding anyone to a project.
Critical Distinction: Two Independent Role Tiers
Set when creating a user account. Controls what the user can do across the entire Ontario environment. Two options: Ontario Admin or Ontario Member.
Assigned when adding a user to a specific project. Controls access within that project only. Two options: Project Admin or Project Member.
An Ontario Member can be a Project Admin. Ontario Admins can see all projects automatically. These tiers are fully independent.
Ontario-Level Roles
Every user account in Ontario carries one of these two roles, set at the time the account is created.
Ontario Admin
Full access to everything at the Ontario level: create and manage all users, groups, and projects. Ontario Admins are the only users who can access the full Users tab on the landing page.
- Create, edit, and deactivate users
- Manage groups and group membership
- Create and configure projects
- Assign users to any project with any role
- Access all Ontario-level settings
- See all projects automatically
Ontario Member
No access by default. An Ontario Member account has no visibility into projects, files, or platform settings until explicitly assigned to a project. Use this role when you want to control exactly what a user can see.
- The user needs access to one or more specific projects
- You want to manage exactly which projects they can see
- The user is a client, external partner, or limited collaborator
- You're adding them to multiple projects from the Ontario Users tab in a single workflow
Project-Level Roles
When a user is added to a project, they receive one of two project-level roles. These roles are independent of their Ontario-level role and control what they can see and do within that specific project—including their default access to files and folders in Harness.
Project Admin
Full management authority within the project. Has unrestricted access to all files and folders in Harness, all tasks, and all project settings.
- Access to all files and folders in Harness by default
- Add and remove project members
- Modify member roles within the project
- Edit project settings and metadata
- Configure workflows and permissions
- Deactivate or delete the project
Project Member
A view-only starting point. Project Members have no default access to files or folders in Harness—access must be explicitly granted at the folder level. They can comment and work on tasks they've been assigned.
- Access only folders/files explicitly shared with them in Harness
- View and comment on tasks they've been assigned
- Collaborate on workflows they've been included in
- Receive project notifications
Why this matters for Harness:
Project Admins have automatic access to every folder and file in Harness within their project. Project Members start with no Harness access—this is intentional, so you can grant access only to the specific folders or files a person needs to see. This makes the Member role the right choice whenever you want granular control over what someone can access.
Role Hierarchy Visualized
Sees all projects automatically
No access until assigned
All files & folders
Explicit access only
All files & folders
Explicit access only
Example: A user with an Ontario Member role can be a Project Admin in Project A (with full Harness access), a Project Member in Project B (with only explicitly granted folder access), and have no visibility into Project C at all.
Two Ways to Add Project Members
Users can be added to a project from two locations. These paths are not interchangeable—they have different scope, different capabilities, and are suited to different situations.
When to use each path
- You are an Ontario Admin onboarding a new user
- The user will need access to more than one project
- You want to assign Ontario-level role and project access in one step
- You need to add the user to a group
- You want a complete, manageable user record in Ontario
- You are a Project Admin (not necessarily an Ontario Admin)
- You need to add a single-project user quickly
- The user will only ever need access to this one project
- You're adding an existing Ontario user to your project
Adding users directly from the project page
When a Project Admin adds a brand new user from within the project, that user is created with a Project Role only — no Ontario-level role is assigned, and they won't appear in the full Ontario user management view. This is a deliberate shortcut best suited to users who will never need access beyond this single project. If that changes later, an Ontario Admin will need to update them from the Users tab on the landing page.
Already in Ontario? If you try to add someone from the project page who already exists as an Ontario user, the system will show an error and direct you to add them from the Ontario-level Users tab instead, to prevent duplicate accounts.
Adding Members During Project Creation
The most efficient time to add project members is during project creation. Step 3 of the project creation wizard lets you assign Project Admins who will have immediate access once the project is created.
- During project creation, advance to Step 3: Admins.
- The current user (you) is added as an Admin by default.
- Click the Admin field to open the user search dropdown.
- Search for users by name or email.
- Select/deselect users from the dropdown list.
- Multiple Admins can be selected.
- Complete the remaining project creation steps.
Screenshot: Project Creation - Step 3 Admins
The Admins step showing the current user pre-selected and the dropdown for searching and selecting additional Admins
Note: During project creation, you can only add Admins. To add Members, complete project creation first, then add them through the project's Users section or the Ontario-level Users tab.
Adding Members to Existing Projects
After a project is created, you can add additional members and assign them either Admin or Member roles using either path.
From the Ontario-Level Users Tab
Use this path for new users or when managing a user's access across multiple projects.
- Navigate to the Users tab on the Ontario landing page.
- Locate the user (use search or filters), then click the three-dot menu (â‹®).
- Select Edit.
- In the Edit User panel, scroll to the Projects section.
- Click + Add Project.
- Select the project from the dropdown.
- Choose the role: Admin or Member.
- Click Save.
Screenshot: Edit User - Projects Section
The Edit User panel showing the Projects section with project name dropdown, role selection (Admin/Member), and trash icon to remove
From Within the Project
Project Admins can create brand new users directly from within the project — no existing Ontario account required. Use this path only when you're confident the person will never need access to any other project. If they already exist as an Ontario user, or if they'll likely need multi-project access in future, use the Ontario-level Users tab instead.
- Navigate into the project and access the Users section from the left sidebar.
- Click Add +.
- Enter the user's First Name, Last Name, and Email.
- Choose their project role: Admin or Member.
- Click Add.
Screenshot: Add User Dialog (from Project)
The Add User modal showing First Name, Last Name, Email, and Project Role (Admin/Member). No Ontario Role is set through this path — this creates a project-only user account.
If the person already exists as an Ontario user
Entering an email address that belongs to an existing Ontario user will trigger an error. The system blocks duplicate accounts. To add an existing Ontario user to this project, ask an Ontario Admin to do it from the Ontario-level Users tab.
Adding Members via User Creation (Ontario Level)
When creating a new user from the Ontario landing page, you can assign their Ontario role, add them to groups, and enroll them in projects simultaneously. This is the recommended approach for most users.
- From the landing page, go to the Users tab.
- Click Create +.
- Fill in: First Name, Last Name, and Email.
- Select the Ontario Role: Admin or Member.
- (Optional) Assign the user to Groups.
- In the Projects section, click + Add Project.
- Select the project from the dropdown.
- Choose the project-level role: Admin or Member.
- Repeat steps 6–8 to add the user to additional projects if needed.
- Click Save.
Screenshot: Create User Dialog
The Create User dialog showing Ontario Role dropdown (Admin/Member), optional Groups field, and Projects section with project/role dropdowns and + Add Project button
Managing Project Members Through Groups
User groups provide an efficient way to manage access for teams that work across multiple projects. When you add a group to a project, all current group members receive access with the assigned role.
Adding Groups to Projects
- Navigate to the Groups tab on the landing page.
- Create a new group or edit an existing one.
- In the group editor, go to the Instance/Project section.
- Select the environment or project to add this group to.
- Save the group configuration.
Important: When you add a group to a project, only the current group members are added. Users who join the group after it's been added to a project do not automatically gain project access—you must add them individually or re-add the entire group.
Screenshot: Edit Group Dialog
The Edit Group panel showing Owner dropdown, Members dropdown (with X to remove), and Project(s) section
Viewing Project Members
The Ontario-level Users tab and the project-level Users section display member information filtered to different scopes. They are not equivalent views.
Ontario-Level Users View
The Users tab on the landing page shows all users across the entire Ontario instance with their Ontario-level roles (Admin/Member) and group memberships.
- Search: By name or email (minimum 3 characters)
- Show filters: Filter by Role (Admin/Member) with user counts
- Pagination: Navigate through users (e.g., "1-20 of 92")
- Columns: Name, Email, Role, Group, Date Created, Last Active, Status
Screenshot: Ontario-Level Users Tab
The Users table showing Ontario-level roles (Member/Admin badges), groups as pills, search, filters, and three-dot action menus
Project-Level Users View
Within an individual project, the Users section shows only members assigned to that project with their project-level roles (Admin/Member). Ontario-level role information is not shown here.
Note that this list may include users who were added to the project in different ways: through the Ontario Users tab, added directly by a Project Admin, or provisioned through a portal app (see below).
Screenshot: Project-Level Users View
The Users section within a project showing project roles (Admin/Member badges) and the table filtered to project members only
Portal Apps and Project Membership Coming Soon
Ontario supports portal-type projects—Compass, Catalyst, Diligent Portal, and Smith AI—which manifest as standalone apps. Users can be added to these portal apps with specific row-level security (RLS) permissions within the app itself.
When a user is provisioned through a portal app, they appear in the corresponding project's Users section as a Project Member. Their access within Harness and other project areas follows the same rules as any other Member—they have no default file or folder access until it's explicitly granted.
Note: Portal-based user provisioning is a Coming Soon feature. Full documentation will be available when this capability is released.
User Activity Monitoring
The Ontario landing page includes a User Activity widget that provides quick visibility into recent user actions across your instance.
Click See more → to navigate to the full Users tab for detailed management. If no recent activity exists, the widget displays "Dummy Data. No recently active users available."
Screenshot: User Activity Widget
The User Activity section on the landing page showing recent user actions with Last Active timestamps and a "See more" link
User Management Actions
The three-dot menu (â‹®) next to each user provides access to management actions. Available options differ between the Ontario-level and project-level views.
Ontario-Level Actions
From the Users tab on the landing page:
Screenshot: User Three-Dot Menu
The action menu showing Edit, View details, Assign to group, Duplicate, De-Activate, and Delete options
Project-Level Actions
From within a project's Users section, actions are scoped to that project only:
- Change Role: Switch between Admin and Member for this project
- View Details: See user information and project-specific access
- Remove from Project: Revoke this user's access to the project
Modifying Project Member Roles
You can change a user's project-level role at any time. Role changes take effect immediately.
- Navigate to the project or the Users tab on the Ontario landing page.
- Locate the user whose role you want to change.
- If in the Ontario-level Users tab: click Edit from the three-dot menu, find the project in the Projects section, and change the role dropdown.
- If in the project's Users section: click the three-dot menu (â‹®) and select Change Role.
- Select the new role: Admin or Member.
- Click Save or Confirm.
Changing from Admin to Member: If you demote a Project Admin to Member, they immediately lose access to all Harness files and folders that haven't been explicitly shared with them. Existing work they created remains in the project; only their access level changes.
Removing Members from Projects
Removing a member revokes their access to this project only—their Ontario-level account and access to other projects are unaffected.
From the Ontario-Level Users Tab
- Navigate to the Users tab on the landing page.
- Find the user and click the three-dot menu (⋮) → Edit.
- Scroll to the Projects section.
- Click the trash icon (🗑️) next to the project to remove them from.
- Click Save.
From the Project's Users Section
- Navigate into the project and go to the Users section.
- Find the member and click the three-dot menu (â‹®).
- Select Remove from Project and confirm.
Important: Removal is immediate. The user loses all project access, stops receiving project notifications, and the project disappears from their view. Their historical contributions (files, tasks, comments) remain in the project.
What Happens When You Remove a Member
Effective member management balances accessibility with security. Follow these guidelines to maintain proper project access control.
Grant Member role by default. Only elevate to Admin when the user genuinely needs to manage settings or other members. This matters especially for Harness—Members start with no file access, so you can grant precisely what they need.
Periodically audit your project members list. Remove users who no longer need access and adjust roles as responsibilities shift. Don't forget users added directly from the project page—they won't appear in the Ontario Users tab if they were created without an Ontario-level role.
Use groups to manage access for teams working across multiple projects. This reduces administrative overhead and keeps access consistent—but remember to re-add groups when new members join, since group membership changes don't automatically propagate.
Remove members promptly when they leave the team. Removing from a project is fast, but also consider deactivating their Ontario account entirely if they're leaving the organization.
Assign at least two Project Admins to each project to ensure continuity. Ontario prevents you from removing the last Admin from a project, but having a backup prevents disruption if one Admin is unavailable.
Avoid over-relying on project-level user creation. Users created only from the project page don't have a full Ontario account, making them harder to manage at scale. Reserve this for confirmed single-project users.
Common Scenarios
A new analyst is joining your firm and will need access to three active projects from day one.
→ Create them from the Ontario landing page. Set their Ontario Role to Member, then add all three projects in the same workflow with the appropriate project role for each. One step, clean account, manageable going forward.
A consultant is being brought in to review files for one specific deal. They'll only ever need this project. You're the Project Admin and don't have Ontario Admin rights.
→ Add them from the project's Users section as a Project Member. Enter their details, assign the Member role, and they're in. Grant them access to the relevant folders in Harness separately. If their scope expands later, flag it for an Ontario Admin to upgrade their account.
A long-time team member is taking over as project lead and now needs full management capabilities, including the ability to add members and configure settings.
→ Change their project role from Member to Admin through either the project's Users section or via Edit User from the Ontario-level Users tab. Their access to all Harness files and folders updates immediately.
Your finance team needs to review project data for a quarterly audit but won't be ongoing contributors.
→ Add auditors as Project Members and explicitly grant them access to only the Harness folders relevant to the audit. Set a calendar reminder to remove their access when the audit concludes. Consider a "Finance Audit" group to streamline recurring access cycles.
What's Next
Now that you understand how to manage project members, you're ready to configure team access in Harness and explore additional collaboration features.
Related Articles
Set up projects and configure team access during the creation process
Create Ontario-level users and invite them to your environment
Grant Project Members access to specific files and folders in Harness
Comprehensive guide to user and group administration across your Ontario environment
Understanding Ontario-level and project-level roles and how they work together
Troubleshooting
| Issue | Solution |
|---|---|
| Adding a user from the project page shows an error | The email address already belongs to an existing Ontario user. The system blocks duplicate accounts. Ask an Ontario Admin to add the user from the Ontario-level Users tab instead. |
| User can't access the project after being added | Confirm the user's Ontario account status is Active (not De-Activated) and that the project itself is Active. Ask the user to refresh their browser or log out and back in to sync permissions. |
| Project Member can't see any files in Harness | This is expected. Project Members have no default Harness access. A Project Admin must explicitly grant folder-level access through Harness folder permissions. See File and Folder Permissions. |
| Confusion between Ontario-level roles and project roles | Ontario-level roles (Admin/Member) control platform access across the entire environment. Project-level roles (Admin/Member) control access within a specific project, including Harness. An Ontario Member can be a Project Admin. Check both tiers when troubleshooting. |
| Member reports they can't edit project settings | Only Project Admins can modify project settings. Verify their project-level role in the project's Users section. If they need these permissions, change their project role to Admin. |
| Can't remove the last Admin from a project | Ontario requires at least one Project Admin per project. Add another user as Project Admin first, then remove the original. This safeguard prevents projects from becoming unmanageable. |
| New group members don't have project access | Adding someone to a group after the group was added to a project does not automatically grant project access. Add the new group member to the project individually, or re-add the entire group to update membership. |
| A user created from the project page doesn't appear in the Ontario Users tab | Users added directly from a project without going through the Ontario-level user creation flow are project-only users with no Ontario-level role. If they need full Ontario account management, an Ontario Admin must create a proper user record from the Users tab. Be careful not to create a duplicate account. |
What's Next
Now that you understand how to add members and assign roles within projects, you're ready to explore related capabilities.
Related Articles
Set up projects and configure team access during the creation workflow
Create Ontario-level users and invite them to join your Ontario environment
Grant Project Members access to specific files and folders in Harness
Understanding the difference between Ontario-level and project-level roles
Ontario's two-tier role system—Ontario-level and project-level—gives you precise control at every layer. Ontario Admins set the foundation by creating users, establishing platform access, and seeing all projects automatically. Project Admins refine access further within their projects, controlling exactly which files and folders each Member can see in Harness. In most cases, the clearest and most manageable path is to have your Ontario Admin create and assign users from the Ontario-level Users tab. Use project-level user creation sparingly, and only for users you're confident will remain single-project. Regular access reviews, careful use of the Member role, and timely offboarding keep your environment secure and your team focused on the work that matters.
Comments
0 comments
Article is closed for comments.