From 8cff42c937789bcb9c54045dc31c6b7248cfe4eb Mon Sep 17 00:00:00 2001 From: Nicolas Frati Date: Thu, 1 Oct 2026 21:06:22 +0200 Subject: [PATCH] docs: document Agent Network Admin and Usage Viewer roles (#1009) * docs: document Agent Network Admin and Usage Viewer roles * docs: unwrap hard-wrapped paragraphs in Agent Network usage pages --- .../usage-and-logs/access-logs.mdx | 8 ++++ .../agent-network/usage-and-logs/index.mdx | 6 ++- .../usage-and-logs/usage-overview.mdx | 4 ++ src/pages/manage/team/user-roles.mdx | 40 ++++++++++++++++--- 4 files changed, 52 insertions(+), 6 deletions(-) diff --git a/src/pages/agent-network/usage-and-logs/access-logs.mdx b/src/pages/agent-network/usage-and-logs/access-logs.mdx index a7958487..ad93e6dd 100644 --- a/src/pages/agent-network/usage-and-logs/access-logs.mdx +++ b/src/pages/agent-network/usage-and-logs/access-logs.mdx @@ -11,6 +11,14 @@ and the reason a request was allowed or denied. agent network access logs table

+## Who can see what + +`Owner`, `Admin`, `Auditor`, `Agent Network Admin`, and `Usage Viewer` see every caller's requests. Every other user sees only their own requests. + + + When [prompt collection](/agent-network/usage-and-logs/log-collection) is enabled, access log entries include captured prompts and completions. Any user with one of the roles above can read other users' prompts. See [User Roles](/manage/team/user-roles#agent-network-permissions). + + ## Columns - **Time** diff --git a/src/pages/agent-network/usage-and-logs/index.mdx b/src/pages/agent-network/usage-and-logs/index.mdx index 65a46b6c..da518df1 100644 --- a/src/pages/agent-network/usage-and-logs/index.mdx +++ b/src/pages/agent-network/usage-and-logs/index.mdx @@ -20,4 +20,8 @@ identity, cost attribution, and token usage. Token and cost **usage** is always collected, so dashboards and limits stay accurate even if access-log collection is turned off. The full **access log** (request detail and optional prompts) is retained according to your log -collection settings. \ No newline at end of file +collection settings. + +## Who Can See What + +`Owner`, `Admin`, `Auditor`, `Agent Network Admin`, and `Usage Viewer` see usage and access logs for every caller. Every other user sees only their own. When prompt collection is enabled, access logs include captured prompts, so these roles can read other users' prompts. See [User Roles](/manage/team/user-roles#agent-network-permissions). diff --git a/src/pages/agent-network/usage-and-logs/usage-overview.mdx b/src/pages/agent-network/usage-and-logs/usage-overview.mdx index e45b949c..86adda7a 100644 --- a/src/pages/agent-network/usage-and-logs/usage-overview.mdx +++ b/src/pages/agent-network/usage-and-logs/usage-overview.mdx @@ -22,6 +22,10 @@ Filter the view by: Filters apply to both the chart and the table. +## Who can see what + +`Owner`, `Admin`, `Auditor`, `Agent Network Admin`, and `Usage Viewer` see usage for the whole account. Every other user sees only their own usage. See [User Roles](/manage/team/user-roles#agent-network-permissions). + ## Tokens vs. Cost Switch between input/output token totals and estimated USD spend. Cost is diff --git a/src/pages/manage/team/user-roles.mdx b/src/pages/manage/team/user-roles.mdx index a9a31f1d..fc6aa014 100644 --- a/src/pages/manage/team/user-roles.mdx +++ b/src/pages/manage/team/user-roles.mdx @@ -1,10 +1,10 @@ -import {Note} from "@/components/mdx" +import {Note, Warning} from "@/components/mdx" -export const description = "Understand NetBird's user roles — Owner, Admin, Network Admin, Billing Admin, Auditor, and User — what each can access, and how to assign them." +export const description = "Understand NetBird's user roles: Owner, Admin, Network Admin, Billing Admin, Auditor, User, Agent Network Admin, and Usage Viewer. Learn what each can access and how to assign them." # User Roles -NetBird has six user roles - `Owner`, `Admin`, `Network Admin`, `Billing Admin`, `Auditor`, and `User`. A user's role controls the level of access they have to your account, both in the dashboard and through the management API. +NetBird has eight user roles - `Owner`, `Admin`, `Network Admin`, `Billing Admin`, `Auditor`, `User`, and two roles scoped to [Agent Network](/agent-network), `Agent Network Admin` and `Usage Viewer`. A user's role controls the level of access they have to your account, both in the dashboard and through the management API. ## Permissions at a glance @@ -31,6 +31,23 @@ Rows are grouped by what a `Network Admin` can do, from full access down to no a 2 A `Billing Admin`'s Settings access is limited to **Plans & Billing** and **Invoices**. +## Agent Network permissions + +| Area | Owner | Admin | Auditor | Agent Network Admin | Usage Viewer | User | +| --: | :--: | :--: | :--: | :--: | :--: | :--: | +| Providers | ✅ | ✅ | 📖 | ✅ | 📖3 | ❌ | +| Policies & Guardrails | ✅ | ✅ | 📖 | ✅ | ❌ | ❌ | +| Global Limits | ✅ | ✅ | 📖 | ✅ | ❌ | ❌ | +| Usage | ✅ | ✅ | 📖 | ✅ | 📖 | 📖4 | +| Access Logs | ✅ | ✅ | 📖 | ✅ | 📖 | 📖4 | +| Configuration | ✅ | ✅ | 📖 | ✅ | ❌ | ❌ | + +`Network Admin` and `Billing Admin` have no Agent Network access beyond what every user gets. + +3 A `Usage Viewer` sees the provider list with connection config redacted: no upstream URLs and no operator-supplied header values. + +4 Every user, whatever their role, sees their own usage and their own requests on **Usage & Logs**. + ## Owner The `Owner` has full access to the account and can manage every aspect of it. There can be only one account owner in NetBird. Owners are the only users who can delete the organization account - see [Delete NetBird account](/manage/settings/delete-account) for more. @@ -49,8 +66,21 @@ An `Auditor` can read every configuration in the account but can't modify anythi ## User A `User` has limited access: they can view the peers they own and other peers they're allowed to connect to. +## Agent Network Admin +An `Agent Network Admin` has full control over Agent Network: providers, policies and guardrails, global limits, usage, access logs, and the configuration pages. They have read-only access to users, groups, peers, and account information, which they need to build policies. They have no access to any other part of the account, such as Control Center, Access Control, Network Routing, DNS, Setup Keys, or Reverse Proxy. The **Clusters** tab under Agent Network configuration stays hidden for this role because it requires Reverse Proxy permissions. + +## Usage Viewer +A `Usage Viewer` has read-only access to the Agent Network **Usage** overview and to the account-wide **Access Logs**. They can also read the provider list, with connection config redacted, and users, groups, and peers, which the filters and name columns rely on. They have no access to policies, guardrails, global limits, or Agent Network configuration. + + + When [prompt collection](/agent-network/usage-and-logs/log-collection) is enabled, access logs contain the captured prompts and completions of every user. Granting `Usage Viewer` lets that user read other users' prompts. + + +## Agent Network access for every user +Any signed-in user, whatever their role, sees their own usage and their own requests on **Usage & Logs**. Once an Agent Network policy covers them, they also see the **Connect** page, which lists the providers and models their policies allow. + ## Roles and the API -Roles apply the same way whether a user works in the dashboard or through the [NetBird management API](/api) - a user's permissions over API resources match their role. Every role except `User` can create a personal access token that carries the same permissions as that user's role, so they can interact with the API programmatically. +Roles apply the same way whether a user works in the dashboard or through the [NetBird management API](/api) - a user's permissions over API resources match their role. Every role except `User`, `Agent Network Admin`, and `Usage Viewer` can create a personal access token that carries the same permissions as that user's role, so they can interact with the API programmatically. ## Roles and identity provider sync @@ -62,7 +92,7 @@ To change a user's role, go to the `Team` tab, select the `Users` tab, and click

user list in the Team tab

-Select the desired role from the dropdown: +Select the desired role from the dropdown. `Agent Network Admin` and `Usage Viewer` are under the **Agent Network** tab:

user role dropdown