RBAC
Role‑based access control (RBAC) for Cost Management ensures that the right people can see and act on cost data without over‑exposing sensitive financial information.
Use this guide to define common roles, permission boundaries, and access-control patterns for Cloudaware Cost Management at scale.
Typical Roles and Access
Examples of personas and their needs:
- FinOps/Cost Management team:
- Broad read access across providers, accounts, and business units.
- Ability to configure allocation models, budgets, forecasts, and anomaly rules.
- Access to optimization, commitment, and waste detection views.
- Finance, accounting, and FP&A:
- Read access to cost data at the BU, cost center, and customer level.
- Access to showback and chargeback statements and reconciliation reports.
- Limited or no access to operational configuration, such as ingestion or policies.
- Platform/Cloud Center of Excellence:
- Visibility into cost by platform, region, shared services, and commitments.
- Ability to act on optimization opportunities and coordinate with teams.
- Engineering/Application owners:
- Read access to costs for their own applications, environments, and accounts.
- Visibility into budgets, anomalies, and optimization recommendations that affect their services.
- Executives and business owners:
- High-level dashboards and statements for their portfolios.
- Limited access to detailed per-resource views unless required.
Map these personas to Cloudaware profiles, permission sets, and sharing rules so Cost Management access aligns with existing governance.
Scoping Cost Visibility
Use sharing and row‑level security to restrict cost visibility where required:
- Limit access to billing and chargeback objects by BU, cost center, customer, or application (e.g., in Advanced Analytics dashboards via security predicates like
User.Id == OwnerIdin datasets) - Ensure that reseller/MSP and multi‑tenant views cannot expose one customer’s details to another.
- Protect sensitive fields such as discounts, margins, or contractual rates with field‑level security.
Where possible, reuse the same scoping model as applications and business mapping so users see costs only for the resources they own or support.
Controlling Configuration Changes
Restrict who can:
- Modify ingestion and provider billing integration settings.
- Change allocation rules, shared‑cost models, and business mappings.
- Create or edit budgets, forecasts, and anomaly detection rules.
- Adjust showback & chargeback models and billing cycles.
Treat these as change‑controlled configuration items, with appropriate approval and audit trails, so that financial views remain stable and explainable.
Auditing and Compliance
To support audit and compliance requirements:
- Ensure changes to key Cost Management settings (allocation, budgets, models) are logged and attributable to individual users.
- Periodically review who has access to billing data and financial views, especially when people change roles.
- Align Cost Management RBAC with your organization’s broader access review and certification processes.