Roles and access
CloudMonitor has two independent levels of access, and they combine. Most confusion about “why can’t I see that?” comes from mixing them up.
Level one: your role in the workspace
Section titled “Level one: your role in the workspace”Set under Settings ▸ Users & Access, by an admin.
| Role | What it means |
|---|---|
| Admin | Full run of the workspace. Creates cost groups, manages users, edits allocation rules and virtual tags, changes workspace settings, and counts as owner of every cost group. |
| Member | Everyone else. Sees the cost groups they belong to, and nothing else. |
One person also holds Organization Owner — whoever first set the workspace up. They are an admin who cannot be demoted, unlicensed or archived, so a workspace can never be locked out of its own administration. There is no separate set of powers; it is a safety catch.
Level two: your role on each cost group
Section titled “Level two: your role on each cost group”A cost group is a slice of your spend — a team, a product, an environment. Membership is per group, so you can be an owner of one and a member of another.
| Role | Can |
|---|---|
| Owner | Everything a member can, plus edit the group, set its budget, manage its team, and archive it |
| Member | See the group’s costs, and triage anomalies and recommendations attributed to it |
Every cost group must keep at least one owner, so the last one can’t be removed or demoted.
Admins are treated as owner of every group, which is why an admin never needs adding to one.
What each role can do
Section titled “What each role can do”| Action | Admin | Cost group owner | Cost group member |
|---|---|---|---|
| See a cost group’s costs | All groups | Own groups | Own groups |
| Triage an anomaly or recommendation — comment, postpone, dismiss, reopen | ✅ | ✅ | ✅ |
| Open the affected resource in the Azure portal | ✅ | ✅ | ✅ |
| Edit a cost group, its budget or its team | All groups | Own groups | ❌ |
| Archive a cost group | ✅ | Own groups | ❌ |
| Create a cost group | ✅ | ❌ | ❌ |
| Create a budget | Any scope | Own groups only | ❌ |
| Edit allocation rules | ✅ | View only | View only |
| Manage virtual tags | ✅ | View only | View only |
| Invite users and set roles | ✅ | ❌ | ❌ |
| Change workspace settings, branding and modules | ✅ | ❌ | ❌ |
Nobody marks an anomaly complete — CloudMonitor closes it itself once the spend returns to normal.
Reading the app’s own signals
Section titled “Reading the app’s own signals”- A screen missing from your menu is usually admin-only, or an optional module your organization hasn’t switched on. Both are described on the relevant page in these docs.
- A screen that opens read-only means you can see it but not change it. Allocation rules and virtual tags behave this way for non-admins, deliberately: understanding how spend is routed is useful to everyone, changing it is not.
- “You are not a member of any cost group” means your membership was removed. Ask an admin or the owner of the group you need.
Licenses and archived users
Section titled “Licenses and archived users”Signing in and holding a paid seat are separate things. Settings ▸ Users & Access shows Licensed seats used against your plan, and a user can be invited without one.
Users are Active or Archived. Archiving keeps someone’s history — their comments and the record of what they changed — while stopping them signing in, holding a seat, or appearing in a cost group’s team. It is the right way to handle a leaver; deleting them would tear holes in the audit trail.
An archived user’s old cost-group memberships never grant access, even though the records remain.
Three rules worth knowing before you invite anyone
Section titled “Three rules worth knowing before you invite anyone”- Invitees must use an email address on the Organization Owner’s domain. An invitation to an outside address is refused.
- One person per email address. If someone on the list already uses it, the invitation is refused — change their role from their own row instead.
- Everyone joins the catch-all Unallocated cost group automatically, so a new user always sees the spend that hasn’t been attributed to anyone yet.