Agent skill

Manage Roles

by harness in harness/harness-skills

Manage Harness RBAC roles, role assignments, permissions, and resource groups via MCP v2 tools.

Apache-2.0Auto-check passedBackend & APIs

Install Manage Roles

skills CLI
$ npx skills add harness/harness-skills --skill manage-roles -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install harness/harness-skills manage-roles --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/harness/harness-skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/manage-roles .claude/skills/manage-roles && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
manage-roles
GitHub stars
115
Token cost
~1.5k tokens
SKILL.md length
479 words
Files
2 (incl. references)
Skills in repo
24
Repo updated
First seen
Licence
Apache-2.0

At a glance

Manage Harness RBAC roles, role assignments, permissions, and resource groups via MCP v2 tools.

  • Works in 6 steps: Understand Requirements → List Existing Roles → Check Current Assignments → …
  • Asked to manage access control
  • SKILL.md covers MCP v2 Tools Used, Instructions, Examples and Best Practices, plus 3 more sections
  • Instructions only: no scripts, shell commands, URLs or credentials in SKILL.md

What it does

Manage Roles is an agent skill from harness/harness-skills. Manage Harness RBAC roles, role assignments, permissions, and resource groups via MCP v2 tools. List, create, update, and delete custom roles. View role assignments and permissions for users, groups, and service accounts. Use when asked to manage access control, assign roles, check permissions, create custom roles, review RBAC configuration, onboard users, or audit access. Trigger phrases: manage roles, RBAC, role assignment, user permissions, access control, custom role, resource group, who has access, grant…

Its SKILL.md is about 1.5k tokens, which your agent loads only when the skill is triggered. The skill folder holds 2 other files, including reference files (for example `references/builtin-roles.md`). Compatibility notes: Requires Harness MCP v2 server (harness-mcp-v2)

It sits in Backend & APIs, covering Authorization and RBAC. It works with Model Context Protocol. The repository describes itself as: A collection of structured AI agent skills that enable Claude Code, Cursor, GitHub Copilot, and other AI coding assistants to create, operate, debug, and govern Harness CI/CD… The licence is Apache-2.0.

When your agent uses it

  • Asked to manage access control
  • Check permissions
  • Create custom roles
  • Review RBAC configuration

Example prompts

  • “/manage-roles”

Requirements

  • Compatibility (from SKILL.md): Requires Harness MCP v2 server (harness-mcp-v2)

Workflow steps

6 steps, taken from the step headings in SKILL.md.

  1. Understand Requirements
  2. List Existing Roles
  3. Check Current Assignments
  4. List Available Permissions (for custom roles)
  5. Create Custom Role (if needed)
  6. View Resource Groups

What it can do on your machine

Read from SKILL.md and the folder at commit c25faee. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    No scripts in the folder and no shell commands in SKILL.md.

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

  • Compatibility

    Requires Harness MCP v2 server (harness-mcp-v2)

    From compatibility in the SKILL.md frontmatter.

Context cost

Manage Roles loads about 1.5k tokens when it runs, and up to ~2.2k if it reads all its reference files. Until then it costs about 138 tokens; SKILL.md has 479 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~138
When it runs · the whole SKILL.md, loaded when a task matches
~1.5k
With references · SKILL.md plus every file in references/, read only if the agent opens them
~2.2k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from harness/harness-skills at commit c25faee, republished under its Apache-2.0 licence (© harness). 479 words, ~1,517 tokens.

Download SKILL.mdSave it as .claude/skills/manage-roles/SKILL.md (or your agent's skills folder). This skill also uses 1 other file; get the full folder from GitHub.
name
manage-roles
description
Manage Harness RBAC roles, role assignments, permissions, and resource groups via MCP v2 tools. List, create, update, and delete custom roles. View role assignments and permissions for users, groups, and service accounts. Use when asked to manage access control, assign roles, check permissions, create custom roles, review RBAC configuration, onboard users, or audit access. Trigger phrases: manage roles, RBAC, role assignment, user permissions, access control, custom role, resource group, who has access, grant access, revoke access.
compatibility
Requires Harness MCP v2 server (harness-mcp-v2)
metadata.author
Harness
metadata.version
1.0.0
metadata.mcp-server
harness-mcp-v2
license
Apache-2.0

Manage Roles Skill

Manage Harness RBAC (Role-Based Access Control) via MCP v2 tools.

MCP v2 Tools Used

ToolResource TypeOperations
harness_listroleList all roles
harness_getroleGet role details
harness_createroleCreate custom role
harness_updateroleUpdate custom role
harness_deleteroleDelete custom role
harness_listrole_assignmentList role assignments
harness_getrole_assignmentGet assignment details
harness_listpermissionList available permissions
harness_getpermissionGet permission details
harness_listresource_groupList resource groups
harness_getresource_groupGet resource group details
harness_describeroleDiscover role schema
harness_search--Search across role-related resources

For built-in roles (account/org/project/module), resource groups, common permissions, and role assignment structure, consult references/builtin-roles.md.

Instructions

Step 1: Understand Requirements

Determine:

  • Who needs access (user email, group ID, or service account ID)
  • What level of access (admin, developer, viewer, executor, custom)
  • Where (account, org, project scope)
  • Which resources (all or specific resource group)
Step 2: List Existing Roles
harness_list(
  resource_type="role",
  org_id="<org>",           # optional
  project_id="<project>",   # optional
  search_term="<keyword>"   # optional
)
Step 3: Check Current Assignments
harness_list(
  resource_type="role_assignment",
  org_id="<org>",
  project_id="<project>"
)
Step 4: List Available Permissions (for custom roles)
harness_list(resource_type="permission")
Step 5: Create Custom Role (if needed)
harness_create(
  resource_type="role",
  org_id="<org>",
  project_id="<project>",
  body={
    "identifier": "custom_deployer",
    "name": "Custom Deployer",
    "description": "Can execute pipelines and view services",
    "permissions": [
      "core_pipeline_execute",
      "core_pipeline_view",
      "core_service_view",
      "core_environment_view"
    ]
  }
)

Identifier must match pattern: ^[a-zA-Z_][0-9a-zA-Z_]{0,127}$

Step 6: View Resource Groups
harness_list(resource_type="resource_group", org_id="<org>", project_id="<project>")

Examples

List all roles in a project
/manage-roles
Show me all roles available in the payments project
Check who has admin access
/manage-roles
List all role assignments with admin privileges in the default org
Create a custom read-only deployer role
/manage-roles
Create a custom role called "release-manager" that can execute pipelines,
view services and environments, but cannot edit anything
Audit access for a user
/manage-roles
What roles does jane.smith@company.com have across all projects?
Review resource groups
/manage-roles
Show me all resource groups and what they include

Best Practices

  • Prefer groups over individual users -- assign roles to USER_GROUP for easier management
  • Follow least privilege -- start with viewer roles and add permissions as needed
  • Scope narrowly -- use project-level roles over account-level when possible
  • Use built-in roles first -- create custom roles only when built-in roles do not fit
  • Naming convention: {role}_{principal} for identifiers (e.g., deployer_ops_team)
Show full SKILL.md (223 more words)Show less

Error Handling

ErrorCauseSolution
Role not foundInvalid role identifierBuilt-in roles start with _ -- verify exact identifier
Resource group not foundInvalid resource groupCheck harness_list(resource_type="resource_group")
Principal not foundUser/group/SA does not existVerify the principal exists before assigning
Duplicate identifierRole with same ID existsUse a unique identifier or update the existing role
Permission deniedCaller lacks RBAC management permissionsNeed core_role_view / core_role_edit permissions

Performance Notes

  • List existing roles and resource groups before creating new ones to avoid duplication.
  • Verify role permissions match the principle of least privilege.
  • Confirm user/group identifiers are correct before assigning roles — incorrect assignments may grant unintended access.

Troubleshooting

User Cannot Access Resources
  1. List role assignments for the user to confirm a role is assigned
  2. Check the role has the required permissions (harness_get on the role)
  3. Verify the resource group scope includes the target resources
  4. Check that the assignment is not disabled: true
Custom Role Not Working
  1. Verify all required permissions are included (e.g., _view permission is needed alongside _edit)
  2. Check the role is assigned at the correct scope (account/org/project)
  3. Confirm the resource group matches the resources the user needs
Permission Denied When Managing Roles
  1. The caller needs core_role_edit to create/update roles
  2. The caller needs core_roleassignment_edit to manage assignments
  3. Account-level operations require account admin or equivalent

© harness, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 1 other file (references) in skills/manage-roles of harness/harness-skills.

  • SKILL.md
  • references/builtin-roles.md

Open the folder on GitHubat commit c25faee

Compare with similar skills

Manage Roles next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Manage Roles compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Manage Roles this skillharness/harness-skills115—~1.5kAutomated safety check: PassApache-2.0
Tenuo Agent Authorizationtenuo-ai/tenuo103—~2.3kAutomated safety check: PassApache-2.0
Frontmcp Auth UIagentfront/frontmcp146—~3.7kAutomated safety check: PassApache-2.0
Frontmcp Authoritiesagentfront/frontmcp146—~7.1kAutomated safety check: PassApache-2.0
Workosusenotra/notra256—~6.2kAutomated safety check: PassAGPL-3.0
Manage Dashboard WidgetsPostHog/posthog40k—~2.3kAutomated safety check: PassCustom licence

Similar skills

  • Add or retrofit Tenuo authorization for AI-agent tools and effects.

    103 GitHub stars~2.3k tokensUpdated today
    Backend & APIsAuto-check passed
  • Frontmcp Auth UI

    agentfront/frontmcp

    A skill your agent uses when customizing, branding, or replacing the built-in FrontMCP OAuth pages (the login, consent, federated-select, incremental-authorization, and error pages) with your own…

    146 GitHub stars~3.7k tokensUpdated today
    Backend & APIsAuto-check passed
  • Frontmcp Authorities

    agentfront/frontmcp

    A skill your agent uses when implementing authorization and access control for FrontMCP tools, resources, prompts, or skills, deciding who may invoke what.

    146 GitHub stars~7.1k tokensUpdated today
    Backend & APIsAuto-check passed
  • Workos

    usenotra/notra

    A skill your agent uses when the user asks for a WorkOS docs URL, term, or dashboard field (Sign-in endpoint, initiateloginuri, Redirect URI, WORKOS env vars), or is implementing, debugging, or…

    256 GitHub stars~6.2k tokensUpdated today
    Backend & APIsAuto-check passed
  • Official

    Guides PostHog engineers through dashboard widget platform work — ship a new widgettype (WIDGETREGISTRY, catalog, runwidgets, WidgetCard) or update a shipped type (config, query, layout, RBAC, tile…

    40k GitHub stars~2.3k tokensUpdated today
    Backend & APIsAuto-check passed
  • Creating Data Lake Table

    aws/agent-toolkit-for-aws

    Official

    Create managed Iceberg tables using Amazon S3 Tables (s3tables API namespace) with automatic compaction and snapshot management.

    2.8k GitHub starsUsed in 1 repo~2.1k tokens
    Backend & APIsAuto-check passed

More from harness/harness-skills

All 24 skills in this repo
  • Audit Report

    harness/harness-skills

    Generate audit reports and compliance trails using Harness audit trail data via MCP v2 tools.

    115 GitHub stars~1.3k tokensUpdated 3 days ago
    Auto-check passed
  • Chaos Dr Test

    harness/harness-skills

    A skill your agent uses when working with Chaos Engineering steps inside a Harness pipeline.

    115 GitHub stars~2.6k tokensUpdated 3 days ago
    Auto-check passed
  • Chaos Experiment

    harness/harness-skills

    A skill your agent uses when the user asks to create, edit, update, design, or configure a Harness Chaos Experiment — including faults, probes, actions, experiment YAML, fault injection, pod-delete…

    115 GitHub stars~1.6k tokensUpdated 3 days ago
    Auto-check passed
  • Cleanup Feature Flags

    harness/harness-skills

    Remove a launched Harness FME feature flag from application code, keeping the treatment FME serves today, and open a pull request.

    115 GitHub stars~2.4k tokensUpdated 3 days ago
    Auto-check passed
  • Configure Repo Scan

    harness/harness-skills

    Configure code scanning in Harness pipelines using STO security scanners.

    115 GitHub stars~2.2k tokensUpdated 3 days ago
    Auto-check passed
  • Create Agent Template

    harness/harness-skills

    Generate Harness Agent Template files for AI-powered automation agents.

    115 GitHub stars~2.2k tokensUpdated 3 days ago
    Auto-check passed

Categories

Questions about Manage Roles

What does Manage Roles do?

Manage Harness RBAC roles, role assignments, permissions, and resource groups via MCP v2 tools. Manage Roles is an agent skill from harness/harness-skills. Manage Harness RBAC roles, role assignments, permissions, and resource groups via MCP v2 tools.

When should I use Manage Roles?

Manage Roles fits situations like: asked to manage access control; check permissions; create custom roles; review RBAC configuration.

How do I install Manage Roles in Claude Code?

Run `npx skills add harness/harness-skills --skill manage-roles -a claude-code`. Or copy the skill folder (skills/manage-roles in harness/harness-skills) into .claude/skills/manage-roles in your project. Claude Code loads it when a task matches its description.

How do I install Manage Roles in Codex?

Run `npx skills add harness/harness-skills --skill manage-roles -a codex`. Or copy the skill folder (skills/manage-roles in harness/harness-skills) into .agents/skills/manage-roles in your project. Codex loads it when a task matches its description.

Can I use Manage Roles in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add harness/harness-skills --skill manage-roles -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/manage-roles, .gemini/skills/manage-roles, .github/skills/manage-roles and .opencode/skills/manage-roles in your project.

What does Manage Roles need to run?

SKILL.md names no scripts, command-line tools or credentials: Manage Roles is instructions for the agent only. Compatibility (from SKILL.md): Requires Harness MCP v2 server (harness-mcp-v2).

Does Manage Roles access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Manage Roles safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Manage Roles use?

Manage Roles is published under the Apache-2.0 licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Manage Roles use?

About 1.5k tokens (SKILL.md is roughly 6.1k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 647 tokens, read only when the agent opens those files.

What are the alternatives to Manage Roles?

Skills that share tags, products or a category with Manage Roles: Tenuo Agent Authorization (tenuo-ai/tenuo, 103 stars), Frontmcp Auth UI (agentfront/frontmcp, 146 stars), Frontmcp Authorities (agentfront/frontmcp, 146 stars) and Workos (usenotra/notra, 256 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Manage Roles?

harness (a GitHub organization) maintains it in harness/harness-skills, which has 115 GitHub stars. The repository holds 24 skills in this directory. The repository was last updated on October 6, 2026.

Source: harness/harness-skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.