Role-Based Access Control (RBAC)
Overview
You can control what functionalities users can access in Netdata Cloud through the Role-Based Access mechanism. RBAC helps you secure your monitoring infrastructure by ensuring team members only access the data and features they need for their specific responsibilities.
What RBAC enables you to do:
- Restrict access to sensitive monitoring data
- Control who can modify configurations and settings
- Manage billing and subscription access
- Organize teams with appropriate permission levels
- Maintain audit trails of user actions
Choose the Right Role
Role Selection Guide
When assigning roles, consider:
If the user needs to... | Recommended Role |
---|---|
Full system control - manage everything including billing, users, and all configurations | Admin |
Team and infrastructure management - manage users, rooms, and configurations but not billing | Manager |
Active troubleshooting - investigate issues, run diagnostics, create dashboards | Troubleshooter |
View-only access - monitor specific systems without making changes | Observer |
Billing management - handle invoices and payments without system access | Billing |
Quick Reference
Role Comparison by Plan
Role | Community | Homelab | Business | Enterprise On-Prem |
---|---|---|---|---|
Admins can control Spaces, Rooms, Nodes, Users and Billing. They can also access any Room in the Space. | ✔️ | ✔️ | ✔️ | ✔️ |
Managers can manage Rooms and Users. They can access any Room in the Space. | - | ✔️ | ✔️ | ✔️ |
Troubleshooters can only use Netdata to troubleshoot, not manage entities. They need to be assigned to Rooms in the Space. | - | ✔️ | ✔️ | ✔️ |
Observers can only view data in specific Rooms. 💡 Ideal for restricting your customer's access to their own dedicated Rooms. | - | ✔️ | ✔️ | ✔️ |
Billing can handle billing options and invoices. | - | ✔️ | ✔️ | ✔️ |
Key Permissions Summary
Area | Admin | Manager | Troubleshooter | Observer | Billing |
---|---|---|---|---|---|
Space Management | Full control | View only | View only | View only | View only |
User Management | Full control | Most permissions | View users in rooms | View users in rooms | None |
Room Management | Full control | Full control | View assigned rooms | View assigned rooms | None |
Node Management | Full control | View all nodes | None | None | None |
Billing Access | Full control | None | None | None | Full control |
Notifications | Full control | View only | View only | View only | None |
Detailed Permissions
Space Management
Functionality | Admin | Manager | Troubleshooter | Observer | Billing | Notes |
---|---|---|---|---|---|---|
See Space | ✔️ | ✔️ | ✔️ | ✔️ | ✔️ | |
Leave Space | ✔️ | ✔️ | ✔️ | ✔️ | ✔️ | |
Delete Space | ✔️ | - | - | - | - | |
Change name | ✔️ | - | - | - | - | |
Change description | ✔️ | - | - | - | - | |
Change slug | ✔️ | - | - | - | - | |
Change preferred nodes | ✔️ | - | - | - | - |
Node Management
Functionality | Admin | Manager | Troubleshooter | Observer | Billing | Notes |
---|---|---|---|---|---|---|
See all Nodes in Space (All Nodes Room) | ✔️ | ✔️ | - | - | - | |
Connect Node to Space | ✔️ | - | - | - | - | |
Delete Node from Space | ✔️ | - | - | - | - |
User Management
Functionality | Admin | Manager | Troubleshooter | Observer | Billing | Notes |
---|---|---|---|---|---|---|
See all Users in Space | ✔️ | ✔️ | - | - | - | |
Invite new User to Space | ✔️ | ✔️ | - | - | - | |
Delete Pending Invitation to Space | ✔️ | ✔️ | - | - | - | |
Delete User from Space | ✔️ | ✔️ | - | - | - | |
Appoint Administrators | ✔️ | - | - | - | - | |
Appoint Billing user | ✔️ | - | - | - | - | |
Appoint Managers | ✔️ | ✔️ | - | - | - | |
Appoint Troubleshooters | ✔️ | ✔️ | - | - | - | |
Appoint Observer | ✔️ | ✔️ | - | - | - | |
Appoint Member | ✔️ | - | - | - | - | |
See all Users in a Room | ✔️ | ✔️ | ✔️ | ✔️ | - | |
Invite existing user to Room | ✔️ | ✔️ | - | - | - | |
Remove user from Room | ✔️ | ✔️ | - | - | - |
Room Management
Functionality | Admin | Manager | Troubleshooter | Observer | Billing | Notes |
---|---|---|---|---|---|---|
See all Rooms in a Space | ✔️ | ✔️ | - | - | - | |
Join any Room in a Space | ✔️ | ✔️ | - | - | - | |
Leave Room | ✔️ | ✔️ | ✔️ | ✔️ | - | |
Create a new Room in a Space | ✔️ | ✔️ | - | - | - | |
Delete Room | ✔️ | ✔️ | - | - | - | |
Change Room name | ✔️ | ✔️ | - | - | - | |
Change Room description | ✔️ | ✔️ | - | - | - | |
Add existing Nodes to Room | ✔️ | ✔️ | - | - | - | |
Remove Nodes from Room | ✔️ | ✔️ | - | - | - |
Notification Management
Functionality | Admin | Manager | Troubleshooter | Observer | Billing | Notes |
---|---|---|---|---|---|---|
See all configured notifications on a Space | ✔️ | ✔️ | ✔️ | ✔️ | - | |
Add new configuration | ✔️ | - | - | - | - | |
Enable/Disable configuration | ✔️ | - | - | - | - | |
Edit configuration | ✔️ | - | - | - | - | Some exceptions apply depending on service level |
Delete configuration | ✔️ | - | - | - | - | |
Edit personal level notification settings | ✔️ | ✔️ | ✔️ | ✔️ | ✔️ | Manage user notification settings |
See Space Alert notification silencing rules | ✔️ | ✔️ | ✔️ | - | - | |
Add new Space Alert notification silencing rule | ✔️ | ✔️ | - | - | - | |
Enable/Disable Space Alert notification silencing rule | ✔️ | ✔️ | - | - | - | |
Edit Space Alert notification silencing rule | ✔️ | ✔️ | - | - | - | |
Delete Space Alert notification silencing rule | ✔️ | ✔️ | - | - | - | |
See, add, edit or delete personal level Alert notification silencing rule | ✔️ | ✔️ | ✔️ | ✔️ | - |
Dashboards
Functionality | Admin | Manager | Troubleshooter | Observer | Billing | Notes |
---|---|---|---|---|---|---|
See all dashboards in Room | ✔️ | ✔️ | ✔️ | ✔️ | - | |
Add new dashboard to Room | ✔️ | ✔️ | ✔️ | ✔️ | - | |
Edit any dashboard in Room | ✔️ | ✔️ | ✔️ | - | - | |
Edit own dashboard in Room | ✔️ | ✔️ | ✔️ | ✔️ | - | |
Delete any dashboard in Room | ✔️ | ✔️ | ✔️ | - | - | |
Delete own dashboard in Room | ✔️ | ✔️ | ✔️ | ✔️ | - |
Functions
Functionality | Admin | Manager | Troubleshooter | Observer | Billing | Notes |
---|---|---|---|---|---|---|
See all functions in Room | ✔️ | ✔️ | ✔️ | ✔️ | - | |
Run any function in Room | ✔️ | ✔️ | - | - | - | |
Run read-only function in Room | ✔️ | ✔️ | ✔️ | ✔️ | - | |
Run sensitive function in Room | ✔️ | ✔️ | - | - | - |
Events Tab
Functionality | Admin | Manager | Troubleshooter | Observer | Billing | Notes |
---|---|---|---|---|---|---|
See Alert or Topology events | ✔️ | ✔️ | ✔️ | ✔️ | - | |
See Auditing events | ✔️ | ✔️ | ✔️ | ✔️ | - |
Billing
Functionality | Admin | Manager | Troubleshooter | Observer | Billing | Notes |
---|---|---|---|---|---|---|
See Plan & Billing details | ✔️ | - | - | - | ✔️ | Current plan and usage figures |
Update plans | ✔️ | - | - | - | - | This includes cancelling current plan (going to Community plan) |
See invoices | ✔️ | - | - | - | ✔️ | |
Manage payment methods | ✔️ | - | - | - | ✔️ | |
Update billing email | ✔️ | - | - | - | ✔️ |
Dynamic Configuration Manager
Functionality | Admin | Manager | Troubleshooter | Observer | Billing | Notes |
---|---|---|---|---|---|---|
List All (see all configurable items) | ✔️ | ✔️ | ✔️ | ✔️ | ✔️ | |
Enable/Disable | ✔️ | ✔️ | - | - | - | |
Add | ✔️ | ✔️ | - | - | - | |
Update | ✔️ | ✔️ | - | - | - | |
Remove | ✔️ | ✔️ | - | - | - | |
Test | ✔️ | ✔️ | - | - | - | |
View | ✔️ | ✔️ | - | - | - | |
View File Format | ✔️ | ✔️ | - | - | - |
Other Permissions
Functionality | Admin | Manager | Troubleshooter | Observer | Billing | Notes |
---|---|---|---|---|---|---|
See Bookmarks in Space | ✔️ | ✔️ | ✔️ | ✔️ | - | |
Add Bookmark to Space | ✔️ | ✔️ | ✔️ | - | - | |
Delete Bookmark from Space | ✔️ | ✔️ | ✔️ | - | - | |
See Visited Nodes | ✔️ | ✔️ | ✔️ | ✔️ | - | |
Update Visited Nodes | ✔️ | ✔️ | ✔️ | ✔️ | - |
note
Enable, Edit and Add actions over specific notification methods will only be allowed if your plan has access to those (see service classification)
note
Netdata Cloud paid subscription required for all actions except "List All" in Dynamic Configuration Manager.
Do you have any feedback for this page? If so, you can open a new issue on our netdata/learn repository.