Skip to main content
Every user in a project has a role that controls what they can see and do. There are four roles across two scopes: one account-level role and three project-level roles.

Role comparison

Client Administrator

Scope: Account The only account-level role. A Client Administrator can manage all projects across the account and invite users to any project, assigning roles up to and including Client Administrator. They have full access to all Cloud resources in every project, all cost reports (including the reservation cost report), audit logs, and resource reservations.

Project-level roles

The following roles are assigned per project. A user can have different roles in different projects.

Project Administrator

Scope: Project Manages a project and its users. Can invite users and assign roles up to Project Administrator level. Has full read/write access to all Cloud resources in the project, plus cost reports and audit logs for that project.

Project User

Scope: Project Works within a project without managing user access. Resource permissions are identical to Project Administrator — the only difference is that Project User cannot invite or manage other users.

Project Observer

Scope: Project Read-only access to the project. Can view all Cloud resources, cost reports, and audit logs but cannot create, edit, or delete anything.