Roles & Permissions
Four roles control what each user can see and do within your CostLens organization.
CostLens uses four roles to control what each user can see and do within your organization: Admin, Operator, FinOps, and Viewer. Every role can view all cost data; they differ in what they can change.
Roles map to a clean separation of duties:
- FinOps identifies and approves savings (budgets, commitments, allocation).
- Operator executes the infrastructure changes (applies fixes, runs syncs).
- Admin owns the platform (accounts, team, security, automation).
- Viewer observes only.
Admin
Full access, including team and platform management. Everything the other roles can do, plus:
- Add and remove cloud accounts (AWS, Azure, GCP) and their credentials
- Manage the team: invite members, change roles, remove members
- Edit organization settings and security policy (MFA, SSO, alert recipients)
- Configure Auto-Fix rules
- Approve and apply fixes; trigger syncs
- Use the Aevi AI assistant
Operator
Infrastructure remediation and operational writes — no platform management.
- Approve, dismiss, and apply / roll back fixes
- Trigger account syncs and analysis
- Manage budgets and enter unit-economics values
- Acknowledge and mute cost anomalies
- Use the Aevi AI assistant
- ✗ Cannot manage commitments, alert rules, or cost-allocation config
- ✗ Cannot add/remove accounts, manage the team, or change org settings
FinOps
Cost-governance persona — for the cloud-finance owner. Manages the financial-governance surface without infrastructure or platform-admin power.
- Manage budgets and spend alert rules
- Manage commitments (Reserved Instances / Savings Plans — recommendations, settings, and purchase)
- Manage unit economics (metric configuration and value entry)
- Manage cost allocation — the cloud hierarchy and account groups
- Approve and dismiss recommendations (prioritise savings) and acknowledge anomalies
- ✗ Cannot apply or roll back infrastructure fixes (that is Operator/Admin — a deliberate separation of duties)
- ✗ Cannot configure Auto-Fix rules, add/remove accounts, manage the team, or change org security settings
Why a separate FinOps role?
A finance owner needs to manage budgets, commitments, and cost allocation — but should not have to be a full Admin (with account credentials, team management, and security control) to do so, and should not be executing infrastructure changes. FinOps grants exactly the cost-governance surface and nothing more.
Viewer
Read-only. No changes to shared organization data.
- View all dashboards, recommendations, billing, inventory, and fix history
- Manage their own profile, notification preferences, and MFA (self-service is always allowed)
- ✗ Cannot approve, dismiss, or apply fixes
- ✗ Cannot create or edit budgets, commitments, unit economics, or any shared setting
- ✗ Cannot add/remove accounts or manage the team
Permissions summary
| Action | Admin | Operator | FinOps | Viewer |
|---|---|---|---|---|
| View dashboards, billing & inventory | ✓ | ✓ | ✓ | ✓ |
| Approve / dismiss recommendations | ✓ | ✓ | ✓ | ✗ |
| Apply / roll back fixes | ✓ | ✓ | ✗ | ✗ |
| Trigger account sync & analysis | ✓ | ✓ | ✗ | ✗ |
| Acknowledge / mute anomalies | ✓ | ✓ | ✓ | ✗ |
| Manage budgets | ✓ | ✓ | ✓ | ✗ |
| Enter unit-economics values | ✓ | ✓ | ✓ | ✗ |
| Manage spend alert rules | ✓ | ✗ | ✓ | ✗ |
| Manage commitments (RI / Savings Plans) | ✓ | ✗ | ✓ | ✗ |
| Configure unit-economics metrics | ✓ | ✗ | ✓ | ✗ |
| Manage cost allocation (hierarchy, account groups) | ✓ | ✗ | ✓ | ✗ |
| Configure Auto-Fix rules | ✓ | ✗ | ✗ | ✗ |
| Add / remove cloud accounts | ✓ | ✗ | ✗ | ✗ |
| Invite / manage team members | ✓ | ✗ | ✗ | ✗ |
| Edit org settings & security | ✓ | ✗ | ✗ | ✗ |
| Use the Aevi AI assistant | ✓ | ✓ | ✗ | ✗ |
Viewer means read-only everywhere
Viewers can never modify shared organization data through the app or the API. If a Viewer (or any role without the required permission) attempts a restricted action, the request is blocked and the attempt is recorded in your organization's security audit trail.
Changing a user's role
Admins change roles on the Team page — see Team Management. Role changes take effect immediately.