Roles & permissions
CloudQuell organizations use four roles so teammates get the right level of control. Viewers read; contributors manage FinOps content; admins additionally manage members, integrations, and org settings such as the organization name; super_admins control billing, deletion, and the admin and super_admin roles.
Every write is re-checked server-side against your role — even if a demoted user keeps an old browser session, their next action returns a clean “permission required” error.
Super Admin
Section titled “Super Admin”Full control. Typically the founder or org owner. Can:
- Everything an admin can do
- Delete the organization
- Manage billing and subscriptions
- Grant the admin and super_admin roles, and remove other super_admins
- Change core organization settings
Cannot change their own role — this prevents accidental lockout.
Day-to-day operator, typically the engineering lead or FinOps owner. Can:
- Everything a contributor can do
- Invite members and set roles, up to contributor — only a super_admin can grant admin or super_admin
- Remove members (except super_admins)
- Rename the organization
- Add and remove AWS account integrations
- Create, edit, and delete notification channels (Slack, Teams, email)
- Manage organization preferences and view all dashboards
Cannot delete the org, manage billing, or grant or change the admin and super_admin roles.
Contributor
Section titled “Contributor”FinOps practitioner. Manages cost content but not the org itself. Can:
- View all dashboards
- Create, edit, and delete budgets, saved reports, and alert rules
- Manage cost centers and allocation rules
- Create scheduled report emails — personal or team — and attach existing notification channels to them
- Dismiss anomalies and update recommendation status
Cannot invite or manage members, add or remove integrations, create or delete notification channels, or touch billing and org settings. Contributors can use channels an Admin has already created (attach them to an alert or a team report), but only Admins add, edit, delete, or test them.
Viewer
Section titled “Viewer”Read-only access to dashboards and the team roster. Can:
- View cost, savings, anomalies, allocation, and every other dashboard
- See who else is on the team and what alerts and channels are configured
- Create and manage their own alert rules on paid plans — viewers can’t edit or delete rules created by others
Cannot create or change any other content, dismiss anomalies, update recommendations, invite members, or manage billing, integrations, or settings.
Choosing roles
Section titled “Choosing roles”Grant the least privilege that lets someone do their job: viewer for stakeholders who only read, contributor for FinOps practitioners, admin for people who manage the team and connections, and reserve super_admin for owners. Roles are also enforced through the MCP server — a write tool checks your role before making any change.
Next: invite your team.