← All docs
Roles & permissions
Seven fixed roles, so access maps to how security, platform, and finance teams actually divide responsibility.
The roles
super_admin (full control), org_admin (manage members, connections, and API keys), security_engineer (findings and remediation), devops_sre (performance/reliability and infrastructure assets), finops (cost recommendations and reporting), auditor (read-only, plus compliance export), and read_only.
Why fixed roles instead of custom permission sets
A fixed, well-named set of roles is easier to reason about in an access review than an open-ended permission matrix — each role maps directly to a real job function, which is what an auditor or a security review actually wants to see.