Skip to main content

Roles and permissions

DoiT platform supports role-based access control (RBAC), which allows you to manage user access through the combination of roles and permissions.

Required permission​

  • Users Manager

Pre-built roles​

Pre-built roles grant a set of permissions that enables users to perform common business functions, simplifying user access management.

Support User​

The Support User role has the minimum set of permissions, which are also included in other pre-built roles.

PermissionDescription
Issues ViewerAccess Cloud incidents information.
Support RequesterCreate and view expert inquiries.

Standard User and Power User​

The Power User role includes all Standard User permissions and additionally grants access to identity and access management, Flexsave, DataHub, and more.

PermissionDescription
Anomalies ViewerAccess Cost anomalies.
Allocations AdminCreate, delete and manage Allocations.
Budgets ManagerCreate, delete and manage Budgets.
Cloud Analytics UserCreate and access Cloud Analytics resources and Commitment Manager commitments.
Cloud Diagrams UserCreate, view, and manage Cloud Diagrams.
CloudFlow Editor(Power User) Create, view, and manage CloudFlows.
Contracts ViewerProvide access to commercial contracts.
DataHub Admin(Power User) Create, view, and manage DataHub datasets.
Flexsave Admin(Power User) Enable and manage Flexsave.
Insights ManagerAccess Insights.
Issues ViewerAccess Cloud incidents information.
Manage Settings(Power User) Manage your DoiT console account settings.
Metrics Manager(Power User) Create, delete, and manage custom metrics for Cloud Analytics.
Perks ViewerAccess and request ISV solutions.
Sandbox AdminObsolete
Sandbox UserObsolete
Support RequesterCreate and view expert inquiries.
Threads ManagerCreate and manage Threads.
Users Manager(Power User) Manage users and roles; view and manage Single Sign-On and auth provider settings.

Finance User​

PermissionDescription
Anomalies ViewerAccess Cost anomalies.
Billing Profiles AdminCreate and manage billing profiles (including payment methods) and connections to third-party platforms.
Budgets ManagerCreate, delete and manage Budgets.
Cloud Analytics UserCreate and access Cloud Analytics resources and Commitment Manager commitments.
Cloud Diagrams UserCreate, view, and manage Cloud Diagrams.
Contracts ViewerProvide access to commercial contracts.
Flexsave AdminEnable and manage Flexsave.
Insights ManagerAccess Insights.
Invoice ViewerView and pay invoices.
Issues ViewerAccess Cloud incidents information.
Perks ViewerAccess and request ISV solutions.
Support RequesterCreate and view expert inquiries.
Threads ManagerCreate and manage Threads.

IT Manager​

PermissionsCapabilities
Assets ManagerView and manage assets (including managing licenses).
Cloud Diagrams UserCreate, view, and manage Cloud Diagrams.
Issues ViewerAccess Cloud incidents.
Perks ViewerAccess and request ISV solutions.
Support RequesterCreate new and access existing expert inquiries.

Admin​

The Admin role has full access to all features and can manage every aspect of your organization's account, including integrations.

Permissions exclusive to the Admin role​

Below are the permissions exclusive to the Admin role.

PermissionDescription
Cloud Analytics AdminView and manage all Cloud Analytics resources, custom dashboards, labels and Commitment Manager commitments in your organization, regardless of whether they have been shared with you.
CloudFlow ManagerCreate, view, manage, and delete CloudFlows created by other users.

Billing Profile Admin permission​

While the permissions listed above are exclusive, the Admin role also includes the Billing Profiles Admin permission. The Billing Profiles Admin permission enables creation and management of billing profiles (including payment methods) and connections to third-party platforms.

Note

The Finance role also has access to the Billing Profile Admin permissions.

Custom roles​

Create a custom role​

To create a custom user role:

  1. In the DoiT console, select the gear icon () from the top navigation bar, and then select Users and access.

  2. Select Roles from the left-hand menu.

    You will see a list of preset roles as well as custom roles created by your team.

  3. Select Create new role.

    The Roles screen_

  4. Enter a name for the role. You can also use the file icon to add a description to the role.

  5. Choose permissions for the role.

Delete a custom role​

Note

You can't delete custom roles that have been assigned to users.

To delete a custom role:

  1. Select the checkbox next to the role of interest on the Roles page.

  2. Select Delete.

    You'll be asked to confirm the deletion before the role is removed.

Default role​

A default role is the role a new user on your team is auto-provisioned, until a role is explicitly set by an admin. Both pre-built and custom roles can be designated as the default role.

A default role is automatically assigned (auto-provisioned) to new users on your team until an admin explicitly sets a different role. It can be either a pre-built or a custom role.

Caution

If auto provisioning is enabled, any user with an email address from your organization's domain can sign up without being invited.

To set a role as the default role:

  1. Locate the role of interest on the Roles page.

  2. Select the role name to open its configuration page.

  3. Select MAKE DEFAULT in the upper-right corner of the page.

Role ID​

To find the role ID in the DoiT console:

  1. Select the gear icon () from the top navigation bar, and then select Identity & access.

  2. Go to the Roles subsection and select the desired role.

  3. Select the Copy Role ID button in the upper-right corner of the role details screen to copy the Role ID to your system clipboard.

    Copy role Id

Summary: Pre-built Roles and Permissions​

PermissionsAdminFinance UserIT ManagerPower UserStandard UserSupport User
Anomalies Viewerβœ“βœ“βœ“βœ“
Assets Managerβœ“βœ“
Allocations Adminβœ“βœ“βœ“
Billing Profile Adminβœ“βœ“
Budgets Managerβœ“βœ“βœ“βœ“
Cloud Analytics Adminβœ“
Cloud Analytics Userβœ“βœ“βœ“βœ“
Cloud Diagrams Userβœ“βœ“βœ“βœ“βœ“
CloudFlow Managerβœ“
CloudFlow Editorβœ“βœ“
Commitment Managerβœ“βœ“
Contracts Viewerβœ“βœ“βœ“βœ“
DataHub Adminβœ“βœ“
Flexsave Adminβœ“βœ“βœ“
Insights Managerβœ“βœ“βœ“βœ“
Invoice Viewerβœ“βœ“
Issues Viewerβœ“βœ“βœ“βœ“βœ“βœ“
Manage Settingsβœ“βœ“
Metrics Managerβœ“βœ“
Perks Viewerβœ“βœ“βœ“βœ“βœ“
Sandbox Adminβœ“βœ“
Sandbox Userβœ“βœ“βœ“
PerfectScale for Spot Managerβœ“βœ“
Support Requesterβœ“βœ“βœ“βœ“βœ“βœ“
Threads Managerβœ“βœ“βœ“βœ“
Users Managerβœ“βœ“