User Guide
Users & roles
Four-role hierarchy with per-user data scoping and email-based invitations.
Role hierarchy#
👑
Owner
Full platform control — license, SSO, branding, and all admin capabilities. One owner per installation (created during setup).
🛡️
Admin
Manage users, cloud accounts, email, AI, diagnostics. Cannot access license, SSO, or branding settings.
📊
Analyst
Full read/write on reports, recommendations, alerts, budgets. No user management or cloud account access.
👁️
Viewer
Read-only across the platform. Can only manage their own profile in Settings.
Inviting users#
Owners and Admins invite new users from Settings → Users:
- Click Invite User
- Enter the email address and select a role
- Optionally set a data scope (all, by provider, or by subscription)
- An invitation email is sent with a unique accept link (7-day expiry)
- The invitee sets their name and password, and is auto-logged in
Tip
When SSO is configured, invited users skip password setup entirely. They create their account with just a name and are redirected to SSO sign-in.
Data scoping#
Data scoping controls what a user can see, while their role controls what they can do. Three scope levels:
- ✓All subscriptions — user sees everything
- ✓By provider — scope to Azure, AWS, or GCP (includes future subscriptions)
- ✓By subscription — specific subscriptions only
Note
Owner and Admin roles always bypass data scoping and see everything, regardless of any scope assignment. Only Analyst and Viewer roles are affected by scope restrictions.
How scoping propagates#
Once set, scoping cascades across the entire platform:
- ✓Cost Explorer, Analytics, Dashboard — only scoped subscriptions
- ✓Recommendations, Alerts, Budgets — filtered to scoped subscriptions
- ✓Subscription dropdowns — only show accessible subscriptions
- ✓AI Assistant — queries respect user's scope automatically
- ✓Reports — scope selection limited to accessible subscriptions
Managing users#
The Users tab shows active users with role badges, scope indicators, and a context menu for each user:
- ✓Change Role — promote or demote (cannot change own role)
- ✓Edit Scope — update data visibility (Analyst/Viewer only)
- ✓Toggle SSO Sync Override — exempt user from automatic scope sync
- ✓Deactivate / Reactivate — disable access without deleting the account
The Permissions sub-tab shows a read-only reference matrix of what each role can access.