In This Article: Learn how Ontario's Harness feature uses a hierarchical permission model to control who can access and manage your files and folders, ensuring your sensitive data remains secure while enabling collaboration with the right team members.
Â
Understanding Ontario's Permission Model
Ontario uses a two-tier permission system that determines what users can see and do with files and folders. This dual-layer approach ensures that access control works seamlessly across your entire organization while allowing project-specific customization.
Ontario-Level Roles
Your Ontario-wide environmental role determines baseline access across all projects and sets your overall permission ceiling.
Project-Level Roles
Your role within a specific project controls what you can do with files and folders inside that project's Harness structure.
Key Principle: Ontario-level Admins have automatic access to all folders across all projects, regardless of project membership. Project-level users must be added to individual folders to gain access.
How File Visibility Works
File and folder visibility in Ontario follows different rules depending on whether you're an Ontario-level Admin or a project-level user. Here's how access is determined:
Ontario-Level Access Check
Ontario first determines if you're an Ontario-level Admin. If so, you automatically see all folders across all projects without needing to be added explicitly.
Project-Level Folder Access
For project-level users (Admins and Members), you must be explicitly added to each folder you need to access. Being a project member alone does not grant access to folders.
Folder-Level Role Assignment
When project-level users are added to a folder, they're assigned one of four folder-level roles (Owner, Editor, Contributor, or Viewer) that determines their specific capabilities within that folder.
Permission Inheritance from Projects
Files and folders automatically inherit permissions from their parent project. This inheritance system ensures consistent access control without requiring manual configuration for every folder. However, the way this works differs significantly between Ontario-level users and project-level users.
For Ontario-level Admins:
- Automatic access to all folders across all projects in the Ontario environment
- Can see and manage any folder without being explicitly added
- Full administrative capabilities regardless of project membership status
- Do not appear in folder-level permission tabs or User Access lists
For Project-level users (Admins and Members):
- Must be explicitly added to individual folders to gain access
- Being a project member does not automatically grant access to all folders
- Folder access is managed through the "Manage access" panel on a folder-by-folder basis
- When added to a folder, project-level users are assigned one of four folder-level roles
This inheritance model simplifies permission management for Ontario-level Admins while providing granular, folder-specific control for project-level users. Project Admins manage folder access by explicitly adding users and assigning appropriate folder-level roles through the Manage access panel.
Admin vs. Member Capabilities
Your role within a project determines what actions you can perform on files and folders. Here's a detailed breakdown of capabilities for each role:
| Action | Project Admin | Project Member |
|---|---|---|
| View files and folders | YES |
YES |
| Upload files to folders | YES |
YES |
| Preview and download files | YES |
YES |
| Add comments to files/folders | YES |
YES |
| Create new folders | YES |
YES |
| Manage folder access | YES |
NO |
| Share files (notifications) | YES |
NO |
| Rename folders | YES |
NO |
| Move folders | YES |
NO |
| Duplicate folders | YES |
NO |
| Archive/delete folders | YES |
NO |
| Export files | YES |
YES |
Remember: Ontario-level Admins have all Project Admin capabilities automatically, regardless of whether they're formally listed as project members. However, Ontario-level Admins do not appear in folder-level permission tabs or User Access lists.
Managing Folder Access
Project Admins can manage who has access to specific folders within their project's Harness structure. This is done through the "Manage access" option, which opens a side panel showing current users and allowing you to add new ones.
Accessing the Manage Access Panel
There are two ways to open folder access management:
Action Menu (Ellipsis)
Click the ellipsis icon (three-dot menu) next to any folder in the Harness table and select "Manage access" from the dropdown options.
Folder Details Panel
Click on a folder to open its details panel, then navigate to the "User Access" tab to view and manage permissions directly.
Screenshot: Ellipsis menu (action menu) showing "Manage access" option
Displaying the dropdown with Rename, Favorite, Create Folder, Upload, Manage access, Move, Duplicate, Archive, and Delete options
Understanding User Access Roles (Folder-Level)
When you open the Manage access panel or User Access tab, you can assign one of four folder-level roles to control what users can do with the folder. These roles are specific to individual folders and are separate from project-level roles:
Owner
Full control over the folder including ability to manage access, move, rename, and delete. Note that Ontario-level Admins do not appear in folder permission tabs, though they have full Owner capabilities across all folders.
Editor
Can upload files, create subfolders, add comments, and modify folder contents. Cannot manage access permissions, move, rename, or delete the folder itself.
Contributor
Can upload files and add comments but cannot create new folders or modify folder structure. Useful for users who need to add content without organizational control.
Viewer
Read-only access. Can view, preview, download, and export files but cannot upload, modify, or add comments. Ideal for stakeholders who need visibility without editing rights.
Screenshot: User Access tab showing project members with folder-level roles
Displaying project members with their assigned folder-level roles (Owner, Editor, Contributor, or Viewer)
Adding Users to Folders
When you need to provide folder-specific access to project members, use the Add User functionality:
Open User Access
Navigate to the folder's User Access tab or click "Manage access" from the ellipsis menu to open the access management panel.
Select Users and Folder-Level Role
Use the "Select users & groups" dropdown to choose one or more users from your project. Then select their folder-level role (Owner, Editor, Contributor, or Viewer) from the role dropdown.
Enable Notifications (Optional)
Check the "Notify Users" checkbox if you want selected users to receive an email notification and an in-app notification alerting them to their new folder access.
Share Access
Click the "Share" button to grant access. Users will appear in the "User with access" list and can immediately access the folder based on their assigned folder-level role.
Screenshot: Add User dialog with folder-level role selection dropdown
Showing user selection dropdown, folder-level role options (Owner, Editor, Contributor, Viewer), Notify Users checkbox, and Share button
Managing folder access this way provides granular control beyond basic project membership. Users added to specific folders receive access tailored to their needs for that particular content through folder-level role assignment.
Sharing Files with Project Members
File sharing in Ontario allows users to send shareable links to files, making it easy to draw attention to specific content or provide quick access to important documents.
How File Sharing Works
Locate the File
Navigate to the file in your Harness folder structure and click the ellipsis menu (action menu) next to the file name. Select "Share" from the dropdown options.
Generate Shareable Link
A shareable link dialog appears where you can copy a direct link to the file. This link can be shared with anyone who needs access to the specific file.
Send Notifications (Optional)
You can also notify specific project members about the file by selecting users and checking the "Notify Users" checkbox. Selected users will receive both an email and an in-app notification. To learn more about notifications, see Understanding Ontario Notifications.
Share the Link
Copy the shareable link and distribute it via email, chat, or any communication channel. Anyone with the link who also has appropriate folder access can view the file.
Screenshot: Share File dialog showing shareable link and notification options
Displaying shareable link field, copy button, user selection dropdown, Notify Users checkbox, and Share button
Understanding Sharing vs. Access Management
It's important to distinguish between two different concepts in Ontario:
- Sharing (for files): Creates a shareable link to a file that can be distributed via any communication channel. Recipients must still have appropriate folder access to view the file—the link simply provides a direct path to the content.
- Managing Access (for folders): Actually controls who can view and interact with a folder by assigning specific folder-level roles (Owner, Editor, Contributor, Viewer). This grants access to users and defines their capabilities within that folder.
Think of file sharing as providing a direct link or "bookmark" to content, while folder access management controls the underlying permissions to view and interact with that content.
Note: Shareable links provide convenient access to files, but recipients still need the appropriate folder-level permissions to view the content. If a user doesn't have access to the folder containing the file, the link will not work for them.
Viewing File and Folder Activities
Ontario automatically tracks user activities on files and folders, creating an audit trail that helps teams understand who's accessing and modifying content.
Understanding System-Generated Comments
When you open a folder's details panel and navigate to the Comments tab, you'll see both user comments and system-generated activity logs. These comments create a complete history of what's happened to files and folders:
Activity Trail & Audit Log
Folder relocated from one location to another within the project structure
Folder moved to the Archive tab for long-term storage while remaining accessible
Folder name changed by a user with appropriate permissions
Folder structure duplicated to create a new parallel folder hierarchy
User permissions added, removed, or modified for the folder
Manual comments and notes added by team members appear with their profile icons
System comments appear with the Ontario icon and "System" label, while user-generated comments display the individual's profile icon. This visual distinction makes it easy to differentiate between automated system activities and manual team collaboration.
Screenshot: Comments tab showing system-generated comments with Ontario icon
Displaying mix of user comments with profile icons and system comments with "System" label and Ontario icon, including timestamps
Bulk Actions and Multi-Select
Project Admins can perform actions on multiple folders simultaneously using the checkbox selection feature in the Harness table view. This saves significant time when reorganizing or managing large sets of content.
Selecting Multiple Items
Click the checkbox to the left of each folder row to select it. As you select folders, a bulk action toolbar appears at the bottom of your screen showing how many items you've selected and which actions are available.
Available Bulk Actions
When you select multiple folders, these actions become available in the bulk toolbar at the bottom of your screen:
Move
Relocate all selected folders to a different location
Duplicate
Create copies of folder structures (files not duplicated)
Archive
Move all selected folders to the Archive tab
Export
Download selected folders as compressed archives
Delete
Permanently remove selected folders (requires confirmation)
Screenshot: Harness table with multiple folders selected
Showing checkboxes selected and bulk action toolbar at bottom with "2 Selected" count and action buttons for Move, Duplicate, Archive, Export, and Delete
Bulk actions respect your permission level—Project Members won't see options for actions they can't perform, such as moving or deleting folders. The bulk action toolbar only displays capabilities available to your role.
Efficiency Tip: When reorganizing project structures or cleaning up old content, use bulk actions to move or archive dozens of folders at once rather than processing them individually. This is particularly useful during project phase transitions or quarterly cleanups.
Learning Check: Test Your Understanding
Can a Project Member delete folders in Harness?
Answer: No. Project Members can view and upload files, but they cannot delete folders. Only Project Admins and Ontario-level Admins have the ability to delete folders from the Harness structure.
What's the difference between sharing a file and managing folder access?
Answer: Sharing a file creates a shareable link that provides a direct path to the file. Managing folder access actually controls who can view and interact with a folder by assigning specific folder-level roles (Owner, Editor, Contributor, Viewer). Think of sharing as providing a bookmark, while access management controls the underlying permissions.
Why don't Ontario-level Admins appear in folder permission tabs?
Answer: Ontario-level Admins have automatic, unrestricted access to all folders across all projects in your Ontario environment. They don't appear in folder permission tabs because they don't need to be explicitly added—their access is automatic and organization-wide. This ensures that organizational administrators can always manage and audit content without being listed in every folder's user list.
What are the four folder-level access roles, and what can each one do?
Answer: Owner has full control including managing access, moving, renaming, and deleting. Editor can upload files, create subfolders, and add comments but cannot manage permissions or delete the folder. Contributor can upload files and add comments but cannot create folders or modify structure. Viewer has read-only access—can view, preview, download, and export but cannot upload or modify anything.
What's Next
Working with Project Members
Learn how to add users to projects and assign their roles
User Roles and Permissions
Understand environment-level and project-level roles in detail
File Actions and Collaboration
Explore all available actions for working with files and folders
Permission management in Ontario is designed around a simple principle: Ontario-level Admins have automatic access to everything, while project-level users must be explicitly added to folders with specific folder-level roles. Ontario-level Admins don't appear in permission tabs because their access is organization-wide and automatic. For project-level users, folder access is managed through explicit role assignment (Owner, Editor, Contributor, or Viewer) via the Manage access panel. This model keeps permission management straightforward while providing the granular control needed for secure collaboration.
Comments
0 comments
Article is closed for comments.