Docs
Open the console →
Reference

Roles & capabilities reference

A quick reference table of every Cloud Control role and the capabilities it grants — Viewer, Deployer, SRE · Cloud Admin, Org Admin, Owner and platform admin.

A condensed reference. For the full explanation and enforcement rules, see the Roles & permissions guide.

Capability matrix

Rolereadmutate_inframanage_cloud_accountsmanage_users_ssomanage_billing_transfer
Viewer
Deployer
SRE · Cloud Admin
Org Admin
Owner
Platform admin✅ (+ all orgs)

What each capability unlocks

CapabilityRepresentative routes
readAll GET reads: /api/console/data, /api/cloud/resources, /api/finops/cost, /api/audit, /api/org/users.
mutate_infraPOST /api/finops/budgets, plan/apply and pipeline actions.
manage_cloud_accountsPOST/DELETE /api/cloud/accounts…, …/validate, …/sync, POST /api/finops/ingest.
manage_users_ssoPOST/PATCH/DELETE /api/org/users…, /api/org/sso, org-wide /api/org/tokens.
manage_billing_transferPOST /api/org/transfer-ownership, billing.
Tokens are capped

An API token's role is a ceiling and never confers owner or platform powers. See API tokens.