# Access model

What a person can do in Costfluent comes from three things: their organization role, the teams they belong to with a team role in each, and the access each of those teams has to a workspace. Costfluent checks every action on the server against that combination.

## Organization roles

Every member of an organization has one organization role. It decides what they can do across the organization.

| Role | Can do across the organization |
|---|---|
| Owner | Everything: organization settings, billing and plans, single sign-on, users and teams, workspaces, connections, API tokens and the audit log. An Owner can do everything in every workspace without being on a team. |
| Integration Owner | Connect and manage cloud accounts, create workspaces and API tokens, set up notification channels. Not users or billing. |
| Editor | Create workspaces and API tokens, sync connections, set up notification channels. |
| Viewer | See the organization and its connections. |

Change a person's role under **Settings**, then **Users**; see [Users, teams and roles](/admin/users-teams-and-roles).

## Team roles and workspace access

Inside a workspace, anyone other than an organization Owner acts through a team. A team has members, each with a team role, and it is granted access to workspaces, each at one level.

| Team role | In a workspace the team can edit |
|---|---|
| Owner | Everything an Editor can, plus rename and delete the workspace and manage who can access it. |
| Editor | Create and change cost reports, dashboards, folders, budgets, alerts, segments, allocation rules, tags and virtual tags, share links and report schedules, and the workspace's data sources; acknowledge anomalies; manage savings items. |
| Viewer | Read cost, reports, dashboards, budgets, anomalies, segments, tags and savings items. |

Every team role can export cost to CSV.

| Workspace access | Effect |
|---|---|
| Can edit | The team's roles apply in full. |
| Can view | Only the read part of the team's roles applies, whatever the role. |
| No access | The team grants nothing in this workspace. |

A person on several teams gets everything any of those teams grants.

## The Everyone team

Every organization has a system team, Everyone. A new workspace gives it the organization's **Default workspace access** until someone grants a team explicit access. Set the default under **Settings**, then **Organization**.

## API tokens

A Public API token carries its own capabilities and, optionally, one workspace. It can never do more than the person who created it could. See [API authentication](/api/authentication).

## Related

- [Users, teams and roles](/admin/users-teams-and-roles)
- [Organization and workspaces](/admin/organization-and-workspaces)
