Troposphere uses a simple three-role model to control access within an organisation. Every user is assigned exactly one role.

Role comparison

CapabilityOwnerAdminMember
View dashboards, costs, and forecasts
View insights and alerts
Manage cost buckets and budgets
Manage connections
Create and edit policies
Invite and remove users
Change user roles
Manage organisation settings
Manage billing and subscription
Delete the organisation

Role descriptions

  • Owner — full control over the organisation, including billing, settings, and the ability to delete the organisation. There must always be at least one Owner.
  • Admin — can manage users, connections, cost buckets, and policies, but cannot change organisation-level settings or billing.
  • Member — read-only access to all dashboards, cost data, insights, and alerts. Cannot modify any configuration.

Note

Role changes take effect immediately. Demoting yourself from Owner is allowed only if at least one other Owner exists.