docs: document Agent Network Admin and Usage Viewer roles (#1009)

* docs: document Agent Network Admin and Usage Viewer roles

* docs: unwrap hard-wrapped paragraphs in Agent Network usage pages
This commit is contained in:
Nicolas Frati
2026-10-01 12:06:22 -07:00
committed by GitHub
parent dff289cb8b
commit 8cff42c937
4 changed files with 52 additions and 6 deletions
@@ -11,6 +11,14 @@ and the reason a request was allowed or denied.
<img src="/docs-static/img/agent-network/usage-and-logs/agent-network-access-logs.png" alt="agent network access logs table" className="imagewrapper-big" />
</p>
## Who can see what
`Owner`, `Admin`, `Auditor`, `Agent Network Admin`, and `Usage Viewer` see every caller's requests. Every other user sees only their own requests.
<Warning>
When [prompt collection](/agent-network/usage-and-logs/log-collection) is enabled, access log entries include captured prompts and completions. Any user with one of the roles above can read other users' prompts. See [User Roles](/manage/team/user-roles#agent-network-permissions).
</Warning>
## Columns
- **Time**
@@ -20,4 +20,8 @@ identity, cost attribution, and token usage.
Token and cost **usage** is always collected, so dashboards and limits stay
accurate even if access-log collection is turned off. The full **access log**
(request detail and optional prompts) is retained according to your log
collection settings.
collection settings.
## Who Can See What
`Owner`, `Admin`, `Auditor`, `Agent Network Admin`, and `Usage Viewer` see usage and access logs for every caller. Every other user sees only their own. When prompt collection is enabled, access logs include captured prompts, so these roles can read other users' prompts. See [User Roles](/manage/team/user-roles#agent-network-permissions).
@@ -22,6 +22,10 @@ Filter the view by:
Filters apply to both the chart and the table.
## Who can see what
`Owner`, `Admin`, `Auditor`, `Agent Network Admin`, and `Usage Viewer` see usage for the whole account. Every other user sees only their own usage. See [User Roles](/manage/team/user-roles#agent-network-permissions).
## Tokens vs. Cost
Switch between input/output token totals and estimated USD spend. Cost is
+35 -5
View File
@@ -1,10 +1,10 @@
import {Note} from "@/components/mdx"
import {Note, Warning} from "@/components/mdx"
export const description = "Understand NetBird's user roles — Owner, Admin, Network Admin, Billing Admin, Auditor, and User — what each can access, and how to assign them."
export const description = "Understand NetBird's user roles: Owner, Admin, Network Admin, Billing Admin, Auditor, User, Agent Network Admin, and Usage Viewer. Learn what each can access and how to assign them."
# User Roles
NetBird has six user roles - `Owner`, `Admin`, `Network Admin`, `Billing Admin`, `Auditor`, and `User`. A user's role controls the level of access they have to your account, both in the dashboard and through the management API.
NetBird has eight user roles - `Owner`, `Admin`, `Network Admin`, `Billing Admin`, `Auditor`, `User`, and two roles scoped to [Agent Network](/agent-network), `Agent Network Admin` and `Usage Viewer`. A user's role controls the level of access they have to your account, both in the dashboard and through the management API.
## Permissions at a glance
@@ -31,6 +31,23 @@ Rows are grouped by what a `Network Admin` can do, from full access down to no a
<sup style={{fontSize: '0.9em', fontWeight: 'bold'}}>2</sup> A `Billing Admin`'s Settings access is limited to **Plans & Billing** and **Invoices**.
## Agent Network permissions
| Area | Owner | Admin | Auditor | Agent Network Admin | Usage Viewer | User |
| --: | :--: | :--: | :--: | :--: | :--: | :--: |
| Providers | ✅ | ✅ | 📖 | ✅ | 📖<sup style={{fontSize: '0.9em', fontWeight: 'bold'}}>3</sup> | ❌ |
| Policies & Guardrails | ✅ | ✅ | 📖 | ✅ | ❌ | ❌ |
| Global Limits | ✅ | ✅ | 📖 | ✅ | ❌ | ❌ |
| Usage | ✅ | ✅ | 📖 | ✅ | 📖 | 📖<sup style={{fontSize: '0.9em', fontWeight: 'bold'}}>4</sup> |
| Access Logs | ✅ | ✅ | 📖 | ✅ | 📖 | 📖<sup style={{fontSize: '0.9em', fontWeight: 'bold'}}>4</sup> |
| Configuration | ✅ | ✅ | 📖 | ✅ | ❌ | ❌ |
`Network Admin` and `Billing Admin` have no Agent Network access beyond what every user gets.
<sup style={{fontSize: '0.9em', fontWeight: 'bold'}}>3</sup> A `Usage Viewer` sees the provider list with connection config redacted: no upstream URLs and no operator-supplied header values.
<sup style={{fontSize: '0.9em', fontWeight: 'bold'}}>4</sup> Every user, whatever their role, sees their own usage and their own requests on **Usage & Logs**.
## Owner
The `Owner` has full access to the account and can manage every aspect of it. There can be only one account owner in NetBird. Owners are the only users who can delete the organization account - see [Delete NetBird account](/manage/settings/delete-account) for more.
@@ -49,8 +66,21 @@ An `Auditor` can read every configuration in the account but can't modify anythi
## User
A `User` has limited access: they can view the peers they own and other peers they're allowed to connect to.
## Agent Network Admin
An `Agent Network Admin` has full control over Agent Network: providers, policies and guardrails, global limits, usage, access logs, and the configuration pages. They have read-only access to users, groups, peers, and account information, which they need to build policies. They have no access to any other part of the account, such as Control Center, Access Control, Network Routing, DNS, Setup Keys, or Reverse Proxy. The **Clusters** tab under Agent Network configuration stays hidden for this role because it requires Reverse Proxy permissions.
## Usage Viewer
A `Usage Viewer` has read-only access to the Agent Network **Usage** overview and to the account-wide **Access Logs**. They can also read the provider list, with connection config redacted, and users, groups, and peers, which the filters and name columns rely on. They have no access to policies, guardrails, global limits, or Agent Network configuration.
<Warning>
When [prompt collection](/agent-network/usage-and-logs/log-collection) is enabled, access logs contain the captured prompts and completions of every user. Granting `Usage Viewer` lets that user read other users' prompts.
</Warning>
## Agent Network access for every user
Any signed-in user, whatever their role, sees their own usage and their own requests on **Usage & Logs**. Once an Agent Network policy covers them, they also see the **Connect** page, which lists the providers and models their policies allow.
## Roles and the API
Roles apply the same way whether a user works in the dashboard or through the [NetBird management API](/api) - a user's permissions over API resources match their role. Every role except `User` can create a personal access token that carries the same permissions as that user's role, so they can interact with the API programmatically.
Roles apply the same way whether a user works in the dashboard or through the [NetBird management API](/api) - a user's permissions over API resources match their role. Every role except `User`, `Agent Network Admin`, and `Usage Viewer` can create a personal access token that carries the same permissions as that user's role, so they can interact with the API programmatically.
## Roles and identity provider sync
<Note>
@@ -62,7 +92,7 @@ To change a user's role, go to the `Team` tab, select the `Users` tab, and click
<p>
<img src="/docs-static/img/manage/team/user-tab-list.png" alt="user list in the Team tab" className="imagewrapper-big"/>
</p>
Select the desired role from the dropdown:
Select the desired role from the dropdown. `Agent Network Admin` and `Usage Viewer` are under the **Agent Network** tab:
<p>
<img src="/docs-static/img/manage/team/user-update-role.png" alt="user role dropdown" className="imagewrapper-big"/>
</p>