Skip to main content

User roles and permissions

The four PointFive roles — Viewer, Editor, Admin and Owner — and what each one can do.

Every PointFive user is assigned one organization-level role: Viewer, Editor, Admin, or Owner. The role determines what a user can do in PointFive. Teams determine which cloud resources they can see. The two work together.

Roles are cumulative: an Editor can do everything a Viewer can, an Admin everything an Editor can, and an Owner everything an Admin can.

The four roles at a glance

Role

Typically for

In one line

Viewer

Stakeholders, finance partners, engineers who only need visibility

Read-only. Can explore, share and export everything in scope, but cannot change any PointFive data.

Editor

Engineers and FinOps practitioners doing the day-to-day work

Everything a Viewer can do, plus acting on findings — statuses, assignments, tickets, dashboards and AI features.

Admin

FinOps leads and platform owners who run the workspace

Everything an Editor can do, plus managing users, teams, detections, datasets and commitments.

Owner

The small group accountable for the account itself

Full access, including cloud provider integrations, SSO and other account-level security settings.

Who can do what

Area

Viewer

Editor

Admin

Owner

View opportunities, resources, anomalies, tags, analytics and the activity log

✔

✔

✔

✔

Share via Slack or email, and export to CSV

✔

✔

✔

✔

Personal saved filters, saved reports, personal dashboards and own API tokens

✔

✔

✔

✔

Update opportunities — status, assignment, comments, dismissals and overrides

—

✔

✔

✔

Configure anomaly rules and update anomaly investigations

—

✔

✔

✔

Create Jira and ServiceNow tickets from PointFive

—

✔

✔

✔

Use Pointer, AI Co-workers and automations

—

✔

✔

✔

Create custom detections and manual opportunities

—

✔

✔

✔

Build and share Cloud Intelligence dashboards

—

✔

✔

✔

Commitments — recommendations, inventory, utilization and effective savings rate

—

—

✔

✔

Manage users and teams — invite, edit roles, team structure and membership

—

—

✔

✔

Platform configuration — Detections Management, Data Explorer datasets, connectors, BI and messaging connections

—

—

✔

✔

Cloud provider integrations — connect, update or remove AWS, Azure, GCP and Kubernetes

—

—

—

✔

Account settings and security — SSO, allowed domains, network settings, service accounts, deleting users

—

—

—

✔

Roles and teams work together

A user's role is set once, at the organization level. It is not set per team.

  • Role answers what can this person do? — for example, whether they can change an opportunity's status.

  • Team membership answers which resources can this person see? — the resources allocated to their teams by allocation rules.

So an Editor in the Data Platform team can act on findings, but only on the resources allocated to that team. Changing someone's teams changes what they see; changing their role changes what they can do.

Roles in the API and MCP server

API tokens and MCP sessions inherit the role of the user they belong to — a token can never grant more access than its owner. A read-and-write token issued by a Viewer still cannot change data.

For backward compatibility, the public GraphQL API continues to report only two role values. See About the PointFive API for the details.

Changing someone's role

Admins and Owners can change roles in Settings → Members. See Managing users and permissions.

Questions? Contact us at support@pointfive.co.

Did this answer your question?