CostLensRoles & Permissions

Roles & Permissions

Four roles control what each user can see and do within your CostLens organization.

Updated August 20263 min read

CostLens uses four roles to control what each user can see and do within your organization: Admin, Operator, FinOps, and Viewer. Every role can view all cost data; they differ in what they can change.

Roles map to a clean separation of duties:

  • FinOps identifies and approves savings (budgets, commitments, allocation).
  • Operator executes the infrastructure changes (applies fixes, runs syncs).
  • Admin owns the platform (accounts, team, security, automation).
  • Viewer observes only.

Admin

Full access, including team and platform management. Everything the other roles can do, plus:

  • Add and remove cloud accounts (AWS, Azure, GCP) and their credentials
  • Manage the team: invite members, change roles, remove members
  • Edit organization settings and security policy (MFA, SSO, alert recipients)
  • Configure Auto-Fix rules
  • Approve and apply fixes; trigger syncs
  • Use the Aevi AI assistant

Operator

Infrastructure remediation and operational writes — no platform management.

  • Approve, dismiss, and apply / roll back fixes
  • Trigger account syncs and analysis
  • Manage budgets and enter unit-economics values
  • Acknowledge and mute cost anomalies
  • Use the Aevi AI assistant
  • ✗ Cannot manage commitments, alert rules, or cost-allocation config
  • ✗ Cannot add/remove accounts, manage the team, or change org settings

FinOps

Cost-governance persona — for the cloud-finance owner. Manages the financial-governance surface without infrastructure or platform-admin power.

  • Manage budgets and spend alert rules
  • Manage commitments (Reserved Instances / Savings Plans — recommendations, settings, and purchase)
  • Manage unit economics (metric configuration and value entry)
  • Manage cost allocation — the cloud hierarchy and account groups
  • Approve and dismiss recommendations (prioritise savings) and acknowledge anomalies
  • Cannot apply or roll back infrastructure fixes (that is Operator/Admin — a deliberate separation of duties)
  • ✗ Cannot configure Auto-Fix rules, add/remove accounts, manage the team, or change org security settings

Why a separate FinOps role?

A finance owner needs to manage budgets, commitments, and cost allocation — but should not have to be a full Admin (with account credentials, team management, and security control) to do so, and should not be executing infrastructure changes. FinOps grants exactly the cost-governance surface and nothing more.

Viewer

Read-only. No changes to shared organization data.

  • View all dashboards, recommendations, billing, inventory, and fix history
  • Manage their own profile, notification preferences, and MFA (self-service is always allowed)
  • ✗ Cannot approve, dismiss, or apply fixes
  • ✗ Cannot create or edit budgets, commitments, unit economics, or any shared setting
  • ✗ Cannot add/remove accounts or manage the team

Permissions summary

ActionAdminOperatorFinOpsViewer
View dashboards, billing & inventory
Approve / dismiss recommendations
Apply / roll back fixes
Trigger account sync & analysis
Acknowledge / mute anomalies
Manage budgets
Enter unit-economics values
Manage spend alert rules
Manage commitments (RI / Savings Plans)
Configure unit-economics metrics
Manage cost allocation (hierarchy, account groups)
Configure Auto-Fix rules
Add / remove cloud accounts
Invite / manage team members
Edit org settings & security
Use the Aevi AI assistant

Viewer means read-only everywhere

Viewers can never modify shared organization data through the app or the API. If a Viewer (or any role without the required permission) attempts a restricted action, the request is blocked and the attempt is recorded in your organization's security audit trail.

Changing a user's role

Admins change roles on the Team page — see Team Management. Role changes take effect immediately.

CostLens
Previous
Team Management
CostLens
Next
B2B Onboarding