Skip to main content

RBAC

Role‑based access control (RBAC) for Cost Management ensures that the right people can see and act on cost data without over‑exposing sensitive financial information.

Use this guide to define common roles, permission boundaries, and access-control patterns for Cloudaware Cost Management at scale.

Typical Roles and Access

Examples of personas and their needs:

  • FinOps/Cost Management team:
    • Broad read access across providers, accounts, and business units.
    • Ability to configure allocation models, budgets, forecasts, and anomaly rules.
    • Access to optimization, commitment, and waste detection views.
  • Finance, accounting, and FP&A:
    • Read access to cost data at the BU, cost center, and customer level.
    • Access to showback and chargeback statements and reconciliation reports.
    • Limited or no access to operational configuration, such as ingestion or policies.
  • Platform/Cloud Center of Excellence:
    • Visibility into cost by platform, region, shared services, and commitments.
    • Ability to act on optimization opportunities and coordinate with teams.
  • Engineering/Application owners:
    • Read access to costs for their own applications, environments, and accounts.
    • Visibility into budgets, anomalies, and optimization recommendations that affect their services.
  • Executives and business owners:
    • High-level dashboards and statements for their portfolios.
    • Limited access to detailed per-resource views unless required.

Map these personas to Cloudaware profiles, permission sets, and sharing rules so Cost Management access aligns with existing governance.

Scoping Cost Visibility

Use sharing and row‑level security to restrict cost visibility where required:

  • Limit access to billing and chargeback objects by BU, cost center, customer, or application (e.g., in Advanced Analytics dashboards via security predicates like User.Id == OwnerId in datasets)
  • Ensure that reseller/MSP and multi‑tenant views cannot expose one customer’s details to another.
  • Protect sensitive fields such as discounts, margins, or contractual rates with field‑level security.

Where possible, reuse the same scoping model as applications and business mapping so users see costs only for the resources they own or support.

Controlling Configuration Changes

Restrict who can:

Treat these as change‑controlled configuration items, with appropriate approval and audit trails, so that financial views remain stable and explainable.

Auditing and Compliance

To support audit and compliance requirements:

  • Ensure changes to key Cost Management settings (allocation, budgets, models) are logged and attributable to individual users.
  • Periodically review who has access to billing data and financial views, especially when people change roles.
  • Align Cost Management RBAC with your organization’s broader access review and certification processes.