In This Article: Ontario uses a three-tier permission model that controls access at the environment, project, and folder levels. This comprehensive guide explains every role type—from environment-level Admins to folder-specific Viewers—what each role can do, how permissions cascade through the system, and strategic guidance for assigning the right access to the right people.
Ontario's Three-Tier Permission Model
Ontario implements a hierarchical permission system that operates at three distinct levels. Each level serves a specific purpose: environment-level roles control platform-wide access, project-level roles determine who can work within specific projects, and folder-level roles provide granular control over individual files and folders within Harness. Understanding how these three tiers work together is essential for maintaining security while enabling collaboration.
The Three Layers of Access Control
Environment-Level Roles
Controls access across the entire Ontario platform. Determines who can create projects, manage users, and access platform-wide settings.
Roles: Admin | Viewer
Project-Level Roles
Controls access within specific projects. Determines who can manage project settings, add members, and configure project structure.
Roles: Admin | Member
Folder-Level Roles (Harness)
Controls access to individual folders and their contents within a project. Provides fine-grained permissions for file management and collaboration.
Roles: Owner | Editor | Contributor | Viewer
These three tiers work together through permission inheritance: higher-level permissions typically grant broader access, while lower-level permissions provide more granular control. For example, an environment-level Admin automatically has access to all projects and folders, while a folder-level Contributor can only add comments to files in their assigned folder.
Tier 1: Environment-Level Roles
Environment-level roles control access to the entire Ontario platform. These roles determine fundamental capabilities like creating projects, managing users across the platform, and accessing environment-wide settings. There are two environment-level roles: Admin and Viewer.
Environment-Level Admin
Environment-level Admins have comprehensive control over the Ontario platform. They serve as platform administrators with the highest level of access and responsibility.
| Capability | What They Can Do |
|---|---|
| User Management | Create, edit, deactivate, and delete user accounts. Change user roles between Admin and Viewer. Invite new users to the platform. |
| Group Management | Create and manage user groups. Add or remove group members. Assign groups to projects with appropriate roles. |
| Project Creation | Create new projects, edit project details, and deactivate projects. Manage project metadata, data sources, and configuration. |
| Universal Project Access | Automatic access to all projects without explicit assignment. Appear as "Admins (Ontario)" in project member lists and folder access panels. |
| Universal Folder Access | Automatic Owner-level access to all folders in Harness across all projects. Cannot be removed from folder access lists. |
| Platform Settings | Configure environment-level settings, manage integrations, and control platform-wide configurations. |
Environment-Level Viewer
Environment-level Viewers have limited platform visibility. They can only access projects to which they've been explicitly added and cannot see the Users or Groups tabs on the Ontario landing page.
Environment Viewers: Limited Platform View
Environment-level Viewers only see the Projects tab on the Ontario landing page—they cannot view or access the Users or Groups tabs. Their landing page displays only projects they've been added to. This design ensures users don't encounter projects or data outside their assigned scope.
While environment-level Viewers have limited platform access, they can be granted Admin rights within specific projects, giving them full control over those projects without platform-wide access.
Screenshot: Environment-Level User Management
Users tab showing role badges (Admin/Viewer labels), with bulk action toolbar for changing roles, activating/deactivating users, and managing group assignments
Tier 2: Project-Level Roles
Project-level roles control access within specific projects. These roles determine who can manage project settings, add or remove team members, configure Harness folder structures, and create tasks. Like environment-level roles, there are two project-level roles: Admin and Member.
Project-Level Admin
Project-level Admins have full control over their assigned projects. They can manage all aspects of the project without affecting other projects or environment-wide settings.
| Capability | What They Can Do |
|---|---|
| Member Management | Add or remove users and groups from the project. Assign project-level Admin or Member roles to project participants. |
| Project Configuration | Edit project name, description, metadata, data sources, companies, and calendar settings. |
| Folder & File Control | Create, rename, move, archive, and delete folders. Upload files. Manage folder-level access permissions through Harness. |
| Task Management | Create tasks, assign them to users, transition task workflow stages, and configure project workflows. |
| Full Data Access | View, edit, upload, download, and export all files within the project. Access all folders regardless of folder-level permissions. |
Project-Level Member
Project-level Members can view and work with project data without the ability to manage team access or alter project structure.
| Capability | What They Can Do |
|---|---|
| View Project Data | Access and view files, folders, and data within folders they've been granted access to via folder-level permissions. |
| File Collaboration | Upload files to folders where granted Editor access. Add comments to files in folders where granted Contributor access. |
| Task Participation | Complete assigned tasks, transition workflow stages for tasks they own, and add comments to tasks. |
| Limited Editing | Cannot delete folders or files, change project settings, manage folder access permissions, or add/remove project members. |
Screenshot: Project Settings - Members Tab
Project settings showing the Members tab with Admin and Member role badges, ellipsis action menu for editing roles, and list of assigned users and groups
Learning Check: Role Level Interactions
Marcus is an environment-level Viewer who's been made a project-level Admin for the "Q1 Financials" project. Can he create new projects or manage users at the environment level?
Aisha is an environment-level Admin. Does she need to be explicitly added to each project to access its files and folders?
Tier 3: Folder-Level Roles (Harness)
Folder-level roles provide granular control over who can access and interact with specific folders and files within a project's Harness file structure. Unlike environment and project roles, folder permissions use four distinct roles: Owner, Editor, Contributor, and Viewer. These roles enable precise control over file collaboration without granting broader project access.
Folder-level permissions are managed through the "Manage access" option in a folder's ellipsis menu (three-dot action menu) or via the "User Access" tab when viewing folder details. Project-level Admins and environment-level Admins can manage folder access, while project-level Members can only view folders they've been granted access to.
Folder Permissions Are Hierarchical
When you set permissions on a folder, those permissions automatically apply to all files and subfolders within it. If you grant someone Editor access to a parent folder, they can upload and edit files in all child folders too. This hierarchical model simplifies permission management while maintaining security.
Folder-Level Role Details
Click each role below to see complete details on what users with that role can and cannot do:
Owner
Full control including managing access
Owner
Full control including managing access
Full administrative control over the folder and all its contents. Can perform all actions including managing access permissions.
What Owners Can Do:
- Manage folder access (add/remove users, change roles)
- Rename, move, duplicate, archive, and delete the folder
- Upload files, create subfolders
- Edit file content, add comments
- Download and export files
Note: Environment-level Admins automatically have Owner access to all folders and cannot be removed.
Editor
Can upload and modify content
Editor
Can upload and modify content
Can modify content within the folder including uploading, editing, and creating subfolders, but cannot manage access or delete the parent folder.
What Editors Can Do:
- Upload files to the folder
- Create subfolders within the folder
- Edit existing file content
- Add comments to files
- Download and export files
- Rename files within the folder
Cannot: Manage folder access, delete/archive the parent folder, or move the folder to another location.
Contributor
Can view and add comments
Contributor
Can view and add comments
Can view and discuss files through comments but cannot upload, edit, or modify folder structure.
What Contributors Can Do:
- View all files in the folder
- Add comments to files
- Reply to existing comment threads
- Download and export files (view-only)
Cannot: Upload files, edit content, create subfolders, or manage access permissions.
Viewer
Read-only access
Viewer
Read-only access
Read-only access to view and download files without any ability to modify, comment, or interact with folder contents.
What Viewers Can Do:
- View all files in the folder
- Download and export files
- See existing comments (but cannot add their own)
Cannot: Add comments, upload files, edit content, create subfolders, or manage permissions. Strictly read-only access.
Screenshot: Folder User Access Panel
Folder detail pane showing the User Access tab with role badges (Owner, Editor, Contributor, Viewer) and the ability to add users and change their folder-level permissions
How the Three Tiers Work Together
Understanding how environment, project, and folder roles interact is crucial for effective access management. The key principle is additive permissions—higher-tier roles generally grant broader access that overrides more restrictive lower-tier permissions.
| Environment Role | Project Role | Folder Role | Effective Access |
|---|---|---|---|
| Admin | Any or None | Any or None | Owner access to everything. Environment Admins bypass all project and folder restrictions. |
| Viewer | Admin | Any or None | Full project control including Owner access to all folders. Project Admins override folder restrictions. |
| Viewer | Member | Owner | Full folder control. Can manage access, upload, edit, and delete within this folder. |
| Viewer | Member | Editor | Can upload and edit folder contents. Cannot manage access or delete the folder. |
| Viewer | Member | Contributor | Can view files and add comments. Cannot upload, edit, or modify structure. |
| Viewer | Member | Viewer | Read-only access. Can view and download files but cannot comment or modify anything. |
| Viewer | Member | Not Added | No folder access. Cannot see or access the folder even though they're a project member. |
Learning Check: Understanding Permission Layers
Jamie is a project-level Member who's been given Viewer access to the "Financial Statements" folder. She needs to upload a new quarterly report to that folder. Can she do this?
Chen is a project-level Admin. Does he need explicit folder-level permissions to access folders within his project?
Strategic Role Assignment
Choosing the right combination of roles requires balancing security, collaboration needs, and operational efficiency. Here are interactive scenarios to guide your decisions:
Platform Administrator
Who: IT staff, platform managers
Env: Admin
Proj: Auto access
Folder: Auto Owner
Full platform oversight without cluttering project lists. Can provide support anywhere when needed.
Project Manager
Who: Team leads, coordinators
Env: Viewer
Proj: Admin
Folder: Auto Owner
Full project control without platform visibility. Can manage team and files independently.
Team Contributor
Who: Analysts, developers
Env: Viewer
Proj: Member
Folder: Editor (work), Viewer (ref)
Can upload/edit in work areas while maintaining read-only access to reference materials.
External Reviewer
Who: Auditors, consultants
Env: Viewer
Proj: Member
Folder: Contributor
Limited access with ability to comment. Cannot upload files or modify structure.
Executive Stakeholder
Who: Leadership, board members
Env: Viewer
Proj: Member
Folder: Viewer
Read-only visibility into key deliverables for oversight without editing access.
PE Deal Team Lead
Who: Private equity professionals
Env: Admin
Proj: Auto access
Folder: Auto Owner
Can create projects for each deal, manage diligence, and maintain isolation between portfolio companies.
Best Practices for Permission Management
Start with Least Privilege
Begin with the minimum permissions necessary for each user's role. It's easier to grant additional access later than to revoke permissions that users have grown dependent on.
Use Groups for Scalability
When multiple users need identical permissions, create a group and assign the group to projects. This simplifies onboarding and ensures consistency as team composition changes.
Leverage Project Membership
Rather than managing folder permissions individually, add users to projects with appropriate project-level roles, then use folder permissions only for exceptions requiring tighter control.
Audit Access Quarterly
Review user permissions every quarter or when roles change. Remove project access for departed team members and adjust permissions for internal transfers or promotions.
Changing Roles at Each Tier
User responsibilities evolve, and Ontario makes it straightforward to adjust permissions at each level. Here's how role changes work across all three tiers.
Changing Environment-Level Roles
Only environment-level Admins can change a user's environment-level role. Navigate to the Users tab on the Ontario landing page, select the user(s) via checkbox, click Change Role in the bulk action toolbar, and choose Admin or Viewer. The change takes effect immediately.
Changing Project-Level Roles
Project-level Admins or environment-level Admins can change project-level roles. Open the project, navigate to Settings Members, click the ellipsis menu next to the user, select Edit, and change their role between Admin and Member. Click Save to apply.
Changing Folder-Level Roles
Project-level Admins or folder Owners can manage folder access. Click the ellipsis menu on a folder and select Manage access, or click a folder and navigate to the User Access tab. From there, you can add users, remove users, or change their folder role (Owner, Editor, Contributor, Viewer) using the dropdown next to their name.
What's Next
Adding and Inviting Users
Step-by-step guide to creating user accounts, sending invitations, and getting new team members set up in Ontario.
Working with Project Members
Learn how to add members to projects, assign project-level roles, and manage team access within specific projects.
File Permissions and Sharing
Deep dive into managing folder-level permissions in Harness, including how to share files and control access to sensitive documents.
Three tiers, one security model: Ontario's layered permission system gives you precise control at every level—from who can create projects across your entire platform down to who can comment on a single folder. Master these three tiers, and you'll maintain airtight security while keeping collaboration flowing smoothly. Start broad with environment roles, narrow to projects, and fine-tune with folder permissions only where needed.
Comments
0 comments
Article is closed for comments.