← All docs

Roles & permissions

Seven fixed roles, so access maps to how security, platform, and finance teams actually divide responsibility.

The roles

super_admin (full control), org_admin (manage members, connections, and API keys), security_engineer (findings and remediation), devops_sre (performance/reliability and infrastructure assets), finops (cost recommendations and reporting), auditor (read-only, plus compliance export), and read_only.

Why fixed roles instead of custom permission sets

A fixed, well-named set of roles is easier to reason about in an access review than an open-ended permission matrix — each role maps directly to a real job function, which is what an auditor or a security review actually wants to see.