Every PointFive user is assigned one organization-level role: Viewer, Editor, Admin, or Owner. The role determines what a user can do in PointFive. Teams determine which cloud resources they can see. The two work together.
Roles are cumulative: an Editor can do everything a Viewer can, an Admin everything an Editor can, and an Owner everything an Admin can.
The four roles at a glance
Role | Typically for | In one line |
Viewer | Stakeholders, finance partners, engineers who only need visibility | Read-only. Can explore, share and export everything in scope, but cannot change any PointFive data. |
Editor | Engineers and FinOps practitioners doing the day-to-day work | Everything a Viewer can do, plus acting on findings — statuses, assignments, tickets, dashboards and AI features. |
Admin | FinOps leads and platform owners who run the workspace | Everything an Editor can do, plus managing users, teams, detections, datasets and commitments. |
Owner | The small group accountable for the account itself | Full access, including cloud provider integrations, SSO and other account-level security settings. |
Who can do what
Area | Viewer | Editor | Admin | Owner |
View opportunities, resources, anomalies, tags, analytics and the activity log | ✔ | ✔ | ✔ | ✔ |
Share via Slack or email, and export to CSV | ✔ | ✔ | ✔ | ✔ |
Personal saved filters, saved reports, personal dashboards and own API tokens | ✔ | ✔ | ✔ | ✔ |
Update opportunities — status, assignment, comments, dismissals and overrides | — | ✔ | ✔ | ✔ |
Configure anomaly rules and update anomaly investigations | — | ✔ | ✔ | ✔ |
Create Jira and ServiceNow tickets from PointFive | — | ✔ | ✔ | ✔ |
Use Pointer, AI Co-workers and automations | — | ✔ | ✔ | ✔ |
Create custom detections and manual opportunities | — | ✔ | ✔ | ✔ |
Build and share Cloud Intelligence dashboards | — | ✔ | ✔ | ✔ |
Commitments — recommendations, inventory, utilization and effective savings rate | — | — | ✔ | ✔ |
Manage users and teams — invite, edit roles, team structure and membership | — | — | ✔ | ✔ |
Platform configuration — Detections Management, Data Explorer datasets, connectors, BI and messaging connections | — | — | ✔ | ✔ |
Cloud provider integrations — connect, update or remove AWS, Azure, GCP and Kubernetes | — | — | — | ✔ |
Account settings and security — SSO, allowed domains, network settings, service accounts, deleting users | — | — | — | ✔ |
Roles and teams work together
A user's role is set once, at the organization level. It is not set per team.
Role answers what can this person do? — for example, whether they can change an opportunity's status.
Team membership answers which resources can this person see? — the resources allocated to their teams by allocation rules.
So an Editor in the Data Platform team can act on findings, but only on the resources allocated to that team. Changing someone's teams changes what they see; changing their role changes what they can do.
Roles in the API and MCP server
API tokens and MCP sessions inherit the role of the user they belong to — a token can never grant more access than its owner. A read-and-write token issued by a Viewer still cannot change data.
For backward compatibility, the public GraphQL API continues to report only two role values. See About the PointFive API for the details.
Changing someone's role
Admins and Owners can change roles in Settings → Members. See Managing users and permissions.
Questions? Contact us at support@pointfive.co.