Costfluent Docs
  • Documentation
  • Guides
  • API Reference
Get started
Concepts
    How Costfluent worksCost amountsAllocation modelAccess modelCurrency settingsAutomatic syncing
Connect a source
Reporting
Allocation
Planning
Optimization
Administration
Developers
Concepts

Access model

What a person can do in Costfluent comes from three things: their organization role, the teams they belong to with a team role in each, and the access each of those teams has to a workspace. Costfluent checks every action on the server against that combination.

Organization roles

Every member of an organization has one organization role. It decides what they can do across the organization.

RoleCan do across the organization
OwnerEverything: organization settings, billing and plans, single sign-on, users and teams, workspaces, connections, API tokens and the audit log. An Owner can do everything in every workspace without being on a team.
Integration OwnerConnect and manage cloud accounts, create workspaces and API tokens, set up notification channels. Not users or billing.
EditorCreate workspaces and API tokens, sync connections, set up notification channels.
ViewerSee the organization and its connections.

Change a person's role under Settings, then Users; see Users, teams and roles.

Team roles and workspace access

Inside a workspace, anyone other than an organization Owner acts through a team. A team has members, each with a team role, and it is granted access to workspaces, each at one level.

Team roleIn a workspace the team can edit
OwnerEverything an Editor can, plus rename and delete the workspace and manage who can access it.
EditorCreate and change cost reports, dashboards, folders, budgets, alerts, segments, allocation rules, tags and virtual tags, share links and report schedules, and the workspace's data sources; acknowledge anomalies; manage savings items.
ViewerRead cost, reports, dashboards, budgets, anomalies, segments, tags and savings items.

Every team role can export cost to CSV.

Workspace accessEffect
Can editThe team's roles apply in full.
Can viewOnly the read part of the team's roles applies, whatever the role.
No accessThe team grants nothing in this workspace.

A person on several teams gets everything any of those teams grants.

The Everyone team

Every organization has a system team, Everyone. A new workspace gives it the organization's Default workspace access until someone grants a team explicit access. Set the default under Settings, then Organization.

API tokens

A Public API token carries its own capabilities and, optionally, one workspace. It can never do more than the person who created it could. See API authentication.

Related

  • Users, teams and roles
  • Organization and workspaces
Last modified on September 30, 2026
Allocation modelCurrency settings
On this page
  • Organization roles
  • Team roles and workspace access
  • The Everyone team
  • API tokens
  • Related