---
title: Roles and access
canonical: "https://cloudmonitor.ai/docs/reference/roles-and-permissions/"
description: "Who can see and change what in CloudMonitor, why a colleague cannot open a screen you can, and who to ask."
---

CloudMonitor has **two independent levels of access**, and they combine. Most confusion about "why
can't I see that?" comes from mixing them up.

## Level one: your role in the workspace

Set under Settings ▸ **Users & Access**, by an admin.

| Role | What it means |
|---|---|
| **Admin** | Full run of the workspace. Creates cost groups, manages users, edits allocation rules and virtual tags, changes workspace settings, and counts as owner of every cost group. |
| **Member** | Everyone else. Sees the cost groups they belong to, and nothing else. |

One person also holds **Organization Owner** — whoever first set the workspace up. They are an admin
who cannot be demoted, unlicensed or archived, so a workspace can never be locked out of its own
administration. There is no separate set of powers; it is a safety catch.

## Level two: your role on each cost group

A **cost group** is a slice of your spend — a team, a product, an environment. Membership is per
group, so you can be an owner of one and a member of another.

| Role | Can |
|---|---|
| **Owner** | Everything a member can, plus edit the group, set its budget, manage its team, and archive it |
| **Member** | See the group's costs, and triage anomalies and recommendations attributed to it |

Every cost group must keep at least one owner, so the last one can't be removed or demoted.

Admins are treated as owner of every group, which is why an admin never needs adding to one.

## What each role can do

| Action | Admin | Cost group owner | Cost group member |
|---|:---:|:---:|:---:|
| See a cost group's costs | All groups | Own groups | Own groups |
| Triage an anomaly or recommendation — comment, postpone, dismiss, reopen | ✅ | ✅ | ✅ |
| Open the affected resource in the Azure portal | ✅ | ✅ | ✅ |
| Edit a cost group, its budget or its team | All groups | Own groups | ❌ |
| Archive a cost group | ✅ | Own groups | ❌ |
| Create a cost group | ✅ | ❌ | ❌ |
| Create a budget | Any scope | Own groups only | ❌ |
| Edit allocation rules | ✅ | View only | View only |
| Manage virtual tags | ✅ | View only | View only |
| Invite users and set roles | ✅ | ❌ | ❌ |
| Change workspace settings, branding and modules | ✅ | ❌ | ❌ |

Nobody marks an anomaly complete — CloudMonitor closes it itself once the spend returns to normal.

## Reading the app's own signals

- **A screen missing from your menu** is usually admin-only, or an optional module your organization
  hasn't switched on. Both are described on the relevant page in these docs.
- **A screen that opens read-only** means you can see it but not change it. Allocation rules and
  virtual tags behave this way for non-admins, deliberately: understanding how spend is routed is
  useful to everyone, changing it is not.
- **"You are not a member of any cost group"** means your membership was removed. Ask an admin or the
  owner of the group you need.

## Licenses and archived users

Signing in and holding a paid seat are separate things. Settings ▸ Users & Access shows
**Licensed seats** used against your plan, and a user can be invited without one.

Users are **Active** or **Archived**. Archiving keeps someone's history — their comments and the
record of what they changed — while stopping them signing in, holding a seat, or appearing in a cost
group's team. It is the right way to handle a leaver; deleting them would tear holes in the audit
trail.

An archived user's old cost-group memberships never grant access, even though the records remain.

## Three rules worth knowing before you invite anyone

- **Invitees must use an email address on the Organization Owner's domain.** An invitation to an
  outside address is refused.
- **One person per email address.** If someone on the list already uses it, the invitation is
  refused — change their role from their own row instead.
- **Everyone joins the catch-all Unallocated cost group automatically**, so a new user always sees
  the spend that hasn't been attributed to anyone yet.
