Skip to content

Roles & permissions

CloudQuell organizations use four roles so teammates get the right level of control. Viewers read; contributors manage FinOps content; admins additionally manage members, integrations, and org settings such as the organization name; super_admins control billing, deletion, and the admin and super_admin roles.

Every write is re-checked server-side against your role — even if a demoted user keeps an old browser session, their next action returns a clean “permission required” error.

Full control. Typically the founder or org owner. Can:

  • Everything an admin can do
  • Delete the organization
  • Manage billing and subscriptions
  • Grant the admin and super_admin roles, and remove other super_admins
  • Change core organization settings

Cannot change their own role — this prevents accidental lockout.

Day-to-day operator, typically the engineering lead or FinOps owner. Can:

  • Everything a contributor can do
  • Invite members and set roles, up to contributor — only a super_admin can grant admin or super_admin
  • Remove members (except super_admins)
  • Rename the organization
  • Add and remove AWS account integrations
  • Create, edit, and delete notification channels (Slack, Teams, email)
  • Manage organization preferences and view all dashboards

Cannot delete the org, manage billing, or grant or change the admin and super_admin roles.

FinOps practitioner. Manages cost content but not the org itself. Can:

Cannot invite or manage members, add or remove integrations, create or delete notification channels, or touch billing and org settings. Contributors can use channels an Admin has already created (attach them to an alert or a team report), but only Admins add, edit, delete, or test them.

Read-only access to dashboards and the team roster. Can:

  • View cost, savings, anomalies, allocation, and every other dashboard
  • See who else is on the team and what alerts and channels are configured
  • Create and manage their own alert rules on paid plans — viewers can’t edit or delete rules created by others

Cannot create or change any other content, dismiss anomalies, update recommendations, invite members, or manage billing, integrations, or settings.

Grant the least privilege that lets someone do their job: viewer for stakeholders who only read, contributor for FinOps practitioners, admin for people who manage the team and connections, and reserve super_admin for owners. Roles are also enforced through the MCP server — a write tool checks your role before making any change.

Next: invite your team.