Access model
What a person can do in Costfluent comes from three things: their organization role, the teams they belong to with a team role in each, and the access each of those teams has to a workspace. Costfluent checks every action on the server against that combination.
Organization roles
Every member of an organization has one organization role. It decides what they can do across the organization.
| Role | Can do across the organization |
|---|---|
| Owner | Everything: organization settings, billing and plans, single sign-on, users and teams, workspaces, connections, API tokens and the audit log. An Owner can do everything in every workspace without being on a team. |
| Integration Owner | Connect and manage cloud accounts, create workspaces and API tokens, set up notification channels. Not users or billing. |
| Editor | Create workspaces and API tokens, sync connections, set up notification channels. |
| Viewer | See the organization and its connections. |
Change a person's role under Settings, then Users; see Users, teams and roles.
Team roles and workspace access
Inside a workspace, anyone other than an organization Owner acts through a team. A team has members, each with a team role, and it is granted access to workspaces, each at one level.
| Team role | In a workspace the team can edit |
|---|---|
| Owner | Everything an Editor can, plus rename and delete the workspace and manage who can access it. |
| Editor | Create and change cost reports, dashboards, folders, budgets, alerts, segments, allocation rules, tags and virtual tags, share links and report schedules, and the workspace's data sources; acknowledge anomalies; manage savings items. |
| Viewer | Read cost, reports, dashboards, budgets, anomalies, segments, tags and savings items. |
Every team role can export cost to CSV.
| Workspace access | Effect |
|---|---|
| Can edit | The team's roles apply in full. |
| Can view | Only the read part of the team's roles applies, whatever the role. |
| No access | The team grants nothing in this workspace. |
A person on several teams gets everything any of those teams grants.
The Everyone team
Every organization has a system team, Everyone. A new workspace gives it the organization's Default workspace access until someone grants a team explicit access. Set the default under Settings, then Organization.
API tokens
A Public API token carries its own capabilities and, optionally, one workspace. It can never do more than the person who created it could. See API authentication.