Authentication

CloudOps uses a role-based access control (RBAC) system to manage user permissions within a workspace. Each user is assigned a role that defines their level of access.

Role Types

CloudOps provides two workspace-level roles:

Workspace Owner

ItemDescription
SummaryFull administrative role with unrestricted access to all workspace features.
User ManagementCan invite new users, remove users, and change user roles.
Resource ManagementCan create, modify, and delete all resources including applications, service accounts, and cloud services.
Cost & BillingFull access to cost analysis, budget configuration, and cost reports.
OperationsCan manage organization structure, service accounts, and event rules.
Alert ManagementCan configure alert services and manage alerts.

Workspace Member

ItemDescription
SummaryStandard role for day-to-day operations with limited management capabilities.
User ManagementCannot invite, remove, or change roles of other users.
Resource ManagementCan view resources and perform operations within the permitted scope.
Cost & BillingCan view cost data and reports.
OperationsCan view organization structure and service account information.
Alert ManagementCan view alerts and alert service configurations.
ℹ️
Both roles are managed roles provided by the system. They cannot be modified or deleted, and custom role creation is not currently supported.

Role Comparison

FeatureWorkspace OwnerWorkspace Member
View dashboard & homeOO
Browse cloud resourcesOO
Create/edit applicationsOX
View cost dataOO
Configure budgets & reportsOX
Invite & manage usersOX
Change user rolesOX
Manage service accountsOX
Configure alert rulesOX
View alertsOO

Role Assignment

  • When a user is invited to the workspace, they are assigned the Workspace Owner role by default.
  • After invitation, a Workspace Owner can change any user’s role via the IAM > Users page.