{
  "meta": {
    "version": "v1",
    "pricing": {
      "public": {
        "label": "Public",
        "description": "Read-only API access for lightweight status checks and public integrations."
      },
      "premium": {
        "label": "Premium",
        "description": "API keys with higher hourly quotas, plus Slack, Discord, webhook, and email outage alerts across your vendor stack."
      }
    },
    "generatedAt": "2026-07-24T10:19:53.653Z"
  },
  "data": {
    "id": "incident_statuspage_harness_9zhcdqmy9vvs",
    "slug": "harness-certain-users-are-unable-to-see-feature-flags-in-prod1-and-prod2-2026-07-14",
    "title": "Certain users are unable to see feature flags in prod1 and prod2",
    "summary": "Certain users are unable to see feature flags in prod1 and prod2",
    "status": "resolved",
    "severity": "minor",
    "startedAt": "2026-07-14T11:25:41.904+00:00",
    "updatedAt": "2026-07-23T22:32:36.677+00:00",
    "resolvedAt": "2026-07-14T11:57:39.917+00:00",
    "provider": {
      "slug": "harness",
      "name": "Harness"
    },
    "affectedServices": [
      {
        "slug": "harness-feature-flags",
        "name": "Feature flags & FME"
      }
    ],
    "links": {
      "html": "/incidents/harness-certain-users-are-unable-to-see-feature-flags-in-prod1-and-prod2-2026-07-14",
      "api": "/api/v1/incidents/harness-certain-users-are-unable-to-see-feature-flags-in-prod1-and-prod2-2026-07-14",
      "providerHtml": "/providers/harness"
    },
    "impactSummary": "Harness reported a minor event for the affected tracked services.",
    "source": {
      "id": "source_harness_status",
      "kind": "official_status_page",
      "name": "Harness Status",
      "checkedAt": "2026-07-23T12:00:00Z",
      "officialUrl": "https://status.harness.io",
      "statusPageUrl": "https://status.harness.io"
    },
    "updates": [
      {
        "id": "update_statuspage_harness_9zhcdqmy9vvs_xtb91sqqh4z4",
        "status": "investigating",
        "body": "Certain users are unable to see feature flags in prod1 and prod2",
        "createdAt": "2026-07-14T11:25:42.017+00:00"
      },
      {
        "id": "update_statuspage_harness_9zhcdqmy9vvs_274jvjdws2vq",
        "status": "monitoring",
        "body": "A fix has been implemented and we are monitoring the results.",
        "createdAt": "2026-07-14T11:56:39.585+00:00"
      },
      {
        "id": "update_statuspage_harness_9zhcdqmy9vvs_d0pk4z4fq7sz",
        "status": "resolved",
        "body": "This incident has been resolved.",
        "createdAt": "2026-07-14T11:57:39.917+00:00"
      },
      {
        "id": "update_statuspage_harness_9zhcdqmy9vvs_1glf7blkqprk",
        "status": "resolved",
        "body": "## Summary\n\nOn July 14, 2026, certain Harness Feature Flag \\(FF\\) Classic customers on the Prod1 and Prod2 production environments were unable to view Feature Flags in the Harness platform. Affected requests returned an authorization error \\(HTTP 403\\), so Feature Flags were not visible for those users until access was restored.\n\nThe behaviour was caused by a planned security update that began requiring an additional Feature Flags permission for related read operations. Users whose roles did not yet include that permission were correctly denied access, which appeared as a product failure. Harness temporarily rolled back the Feature Flags service change to restore access, updated the required permissions for affected users and roles, and confirmed that Feature Flag visibility returned to normal. The stronger permission checks remain in place going forward.\n\n## Impact\n\nDuring the customer-reported incident window on July 14, 2026 \\(status page approximately 11:25 UTC to 11:57 UTC\\):\n\n* Certain Feature Flag Classic customers on **Prod1** and **Prod2** were impacted.\n* Affected users could not view Feature Flags in the Harness UI / API and received **403 Forbidden** responses.\n* Impact was limited to users and roles that did not yet have the updated Feature Flags permission required by the security change.\n* A public status page update was posted for Prod1 and Prod2 Feature Flags.\n\nThere was **no data loss**, no change to stored feature flag configurations, and no impact to Feature Flag evaluation for applications whose SDK credentials and permissions were unaffected. Customers and users with the required permission continued to operate normally.\n\n## Root Cause\n\nHarness deployed a planned Feature Flags authorization update that enforces the `ff_targetgroup_view` permission on target-related read paths used when viewing Feature Flags. This enforcement is intentional and remains the expected behaviour.\n\nUsers and roles that had not yet been granted `ff_targetgroup_view` received 403 responses and could not see Feature Flags. From the customer’s perspective this looked like an outage; it was an authorization denial due to missing required permissions after the security update.\n\n## Mitigation\n\nHarness completed the following mitigation steps:\n\n* Temporarily rolled back the Feature Flags service in Prod2 and Prod1 \\(and aligned Prod0\\) to restore access quickly while permissions were corrected.\n* Updated / granted the required `ff_targetgroup_view` permission for affected users and roles.\n* Verified that Feature Flag visibility returned to normal and closed the status page incident.\n\nThese actions restored customer access. The permission enforcement introduced by the security update **remains in effect** going forward; the lasting fix is correct permission assignment, not removal of the check.\n\n## Preventive Actions\n\nTo avoid a recurrence of this issue, Harness is taking the following actions:\n\n* Keeping the stronger Feature Flags permission checks in place as the permanent security posture.\n* Ensuring role and permission updates for `ff_targetgroup_view` are applied with \\(or before\\) similar authorization changes in production.",
        "createdAt": "2026-07-23T22:32:11.461+00:00"
      }
    ],
    "access": {
      "plan": "public",
      "keyed": false
    }
  }
}