Skip to content

Roles and access

CloudMonitor has two independent levels of access, and they combine. Most confusion about “why can’t I see that?” comes from mixing them up.

Set under Settings ▸ Users & Access, by an admin.

RoleWhat it means
AdminFull run of the workspace. Creates cost groups, manages users, edits allocation rules and virtual tags, changes workspace settings, and counts as owner of every cost group.
MemberEveryone else. Sees the cost groups they belong to, and nothing else.

One person also holds Organization Owner — whoever first set the workspace up. They are an admin who cannot be demoted, unlicensed or archived, so a workspace can never be locked out of its own administration. There is no separate set of powers; it is a safety catch.

A cost group is a slice of your spend — a team, a product, an environment. Membership is per group, so you can be an owner of one and a member of another.

RoleCan
OwnerEverything a member can, plus edit the group, set its budget, manage its team, and archive it
MemberSee the group’s costs, and triage anomalies and recommendations attributed to it

Every cost group must keep at least one owner, so the last one can’t be removed or demoted.

Admins are treated as owner of every group, which is why an admin never needs adding to one.

ActionAdminCost group ownerCost group member
See a cost group’s costsAll groupsOwn groupsOwn groups
Triage an anomaly or recommendation — comment, postpone, dismiss, reopen
Open the affected resource in the Azure portal
Edit a cost group, its budget or its teamAll groupsOwn groups
Archive a cost groupOwn groups
Create a cost group
Create a budgetAny scopeOwn groups only
Edit allocation rulesView onlyView only
Manage virtual tagsView onlyView only
Invite users and set roles
Change workspace settings, branding and modules

Nobody marks an anomaly complete — CloudMonitor closes it itself once the spend returns to normal.

  • A screen missing from your menu is usually admin-only, or an optional module your organization hasn’t switched on. Both are described on the relevant page in these docs.
  • A screen that opens read-only means you can see it but not change it. Allocation rules and virtual tags behave this way for non-admins, deliberately: understanding how spend is routed is useful to everyone, changing it is not.
  • “You are not a member of any cost group” means your membership was removed. Ask an admin or the owner of the group you need.

Signing in and holding a paid seat are separate things. Settings ▸ Users & Access shows Licensed seats used against your plan, and a user can be invited without one.

Users are Active or Archived. Archiving keeps someone’s history — their comments and the record of what they changed — while stopping them signing in, holding a seat, or appearing in a cost group’s team. It is the right way to handle a leaver; deleting them would tear holes in the audit trail.

An archived user’s old cost-group memberships never grant access, even though the records remain.

Three rules worth knowing before you invite anyone

Section titled “Three rules worth knowing before you invite anyone”
  • Invitees must use an email address on the Organization Owner’s domain. An invitation to an outside address is refused.
  • One person per email address. If someone on the list already uses it, the invitation is refused — change their role from their own row instead.
  • Everyone joins the catch-all Unallocated cost group automatically, so a new user always sees the spend that hasn’t been attributed to anyone yet.