Skip to content

Roles & permissions ​

CLARITY uses a three-role access control system to manage what users can see and do. Every user is assigned exactly one role.

Role assignment in the User Management page — change a user's role from the action column

Role overview ​

RoleDescription
AdminFull platform access including user management and all settings
EditorOperational access to manage cloud accounts, syncs, reports, and budgets
ViewerRead-only access to all dashboards, reports, and data

INFO

New user accounts are assigned the Viewer role by default. Only administrators can change a user's role.

Detailed permission matrix ​

ActionAdminEditorViewer
View dashboards and cost dataYesYesYes
View recommendations and insightsYesYesYes
View anomalies and forecastsYesYesYes
View reportsYesYesYes
View audit logYes (Business+)NoNo
Add/edit cloud credentialsYesYesNo
Trigger manual syncYesYesNo
Create and manage budgetsYesYesNo
Create and manage cost centersYesYesNo
Configure allocation rulesYesYesNo
Generate reportsYesYesNo
Generate chargeback statementsYesYesNo
Request AI explanationsYesYesYes
Create user accountsYesNoNo
Delete user accountsYesNoNo
Reset another user's passwordYesNoNo
Edit other users' profilesYes (Business+)NoNo
Assign rolesYes (Business+)NoNo
Delete cloud credentialsYesNoNo

"Business+" rows

These actions additionally require a Business or Enterprise subscription. An administrator on Starter or Pro will receive a permission error. Creating, deleting and password-resetting users are deliberately available on every tier, because they are how you run the seats you have licensed.

Roles restrict actions, not visibility

Every authenticated user — Viewer included — can see every connected cloud account and all of its cost and resource data. There is no per-user or per-team data partitioning. Requesting an AI explanation is also available to Viewers, and it consumes AI credits.

Role assignment ​

Only administrators can assign or change roles:

  1. Go to Organizations and open the Users tab
  2. Select the user account
  3. Choose the new role from the dropdown
  4. Click Save

Role assignment requires a Business or Enterprise subscription.

The role change takes effect on the user's next request. Active sessions are updated automatically.

Choosing the right role ​

Use Admin for people who need to manage the platform itself — creating users, configuring security settings, and managing the full lifecycle of cloud credentials.

Use Editor for FinOps practitioners, DevOps engineers, and team leads who need to manage cloud accounts, trigger syncs, create reports, and configure cost allocation — but should not manage other users.

Use Viewer for stakeholders, managers, and team members who need visibility into cloud costs and optimization opportunities but should not make changes.

TIP

Follow the principle of least privilege. Start users with the Viewer role and upgrade to Editor or Admin only when they need the additional capabilities.

Next steps ​

Multi-Cloud FinOps Platform