Skip to content

Roles & Permissions

CLARITY uses a three-role access control system to manage what users can see and do. Every user is assigned exactly one role.

Role Overview

RoleDescription
AdminFull platform access including user management and all settings
EditorOperational access to manage cloud accounts, syncs, reports, and budgets
ViewerRead-only access to all dashboards, reports, and data

INFO

New user accounts are assigned the Viewer role by default. Only administrators can change a user's role.

Detailed Permission Matrix

ActionAdminEditorViewer
View dashboards and cost dataYesYesYes
View recommendations and insightsYesYesYes
View anomalies and forecastsYesYesYes
View reportsYesYesYes
View audit logYesYesYes
Add/edit cloud credentialsYesYesNo
Trigger manual syncYesYesNo
Create and manage budgetsYesYesNo
Create and manage cost centersYesYesNo
Configure allocation rulesYesYesNo
Generate reportsYesYesNo
Generate chargeback statementsYesYesNo
Request AI explanationsYesYesNo
Create user accountsYesNoNo
Edit other users' profilesYesNoNo
Assign rolesYesNoNo
Activate/deactivate usersYesNoNo
Delete cloud credentialsYesNoNo

Role Assignment

Only administrators can assign or change roles:

  1. Navigate to Administration > Users
  2. Select the user account
  3. Choose the new role from the dropdown
  4. Click Save

The role change takes effect on the user's next request. Active sessions are updated automatically.

Choosing the Right Role

Use Admin for people who need to manage the platform itself — creating users, configuring security settings, and managing the full lifecycle of cloud credentials.

Use Editor for FinOps practitioners, DevOps engineers, and team leads who need to manage cloud accounts, trigger syncs, create reports, and configure cost allocation — but should not manage other users.

Use Viewer for stakeholders, managers, and team members who need visibility into cloud costs and optimization opportunities but should not make changes.

TIP

Follow the principle of least privilege. Start users with the Viewer role and upgrade to Editor or Admin only when they need the additional capabilities.

Next Steps

Multi-Cloud FinOps Platform