mirror of
https://github.com/netbirdio/docs.git
synced 2026-10-02 19:59:05 +02:00
docs: document Agent Network Admin and Usage Viewer roles (#1009)
* docs: document Agent Network Admin and Usage Viewer roles * docs: unwrap hard-wrapped paragraphs in Agent Network usage pages
This commit is contained in:
@@ -11,6 +11,14 @@ and the reason a request was allowed or denied.
|
||||
<img src="/docs-static/img/agent-network/usage-and-logs/agent-network-access-logs.png" alt="agent network access logs table" className="imagewrapper-big" />
|
||||
</p>
|
||||
|
||||
## Who can see what
|
||||
|
||||
`Owner`, `Admin`, `Auditor`, `Agent Network Admin`, and `Usage Viewer` see every caller's requests. Every other user sees only their own requests.
|
||||
|
||||
<Warning>
|
||||
When [prompt collection](/agent-network/usage-and-logs/log-collection) is enabled, access log entries include captured prompts and completions. Any user with one of the roles above can read other users' prompts. See [User Roles](/manage/team/user-roles#agent-network-permissions).
|
||||
</Warning>
|
||||
|
||||
## Columns
|
||||
|
||||
- **Time**
|
||||
|
||||
@@ -20,4 +20,8 @@ identity, cost attribution, and token usage.
|
||||
Token and cost **usage** is always collected, so dashboards and limits stay
|
||||
accurate even if access-log collection is turned off. The full **access log**
|
||||
(request detail and optional prompts) is retained according to your log
|
||||
collection settings.
|
||||
collection settings.
|
||||
|
||||
## Who Can See What
|
||||
|
||||
`Owner`, `Admin`, `Auditor`, `Agent Network Admin`, and `Usage Viewer` see usage and access logs for every caller. Every other user sees only their own. When prompt collection is enabled, access logs include captured prompts, so these roles can read other users' prompts. See [User Roles](/manage/team/user-roles#agent-network-permissions).
|
||||
|
||||
@@ -22,6 +22,10 @@ Filter the view by:
|
||||
|
||||
Filters apply to both the chart and the table.
|
||||
|
||||
## Who can see what
|
||||
|
||||
`Owner`, `Admin`, `Auditor`, `Agent Network Admin`, and `Usage Viewer` see usage for the whole account. Every other user sees only their own usage. See [User Roles](/manage/team/user-roles#agent-network-permissions).
|
||||
|
||||
## Tokens vs. Cost
|
||||
|
||||
Switch between input/output token totals and estimated USD spend. Cost is
|
||||
|
||||
@@ -1,10 +1,10 @@
|
||||
import {Note} from "@/components/mdx"
|
||||
import {Note, Warning} from "@/components/mdx"
|
||||
|
||||
export const description = "Understand NetBird's user roles — Owner, Admin, Network Admin, Billing Admin, Auditor, and User — what each can access, and how to assign them."
|
||||
export const description = "Understand NetBird's user roles: Owner, Admin, Network Admin, Billing Admin, Auditor, User, Agent Network Admin, and Usage Viewer. Learn what each can access and how to assign them."
|
||||
|
||||
# User Roles
|
||||
|
||||
NetBird has six user roles - `Owner`, `Admin`, `Network Admin`, `Billing Admin`, `Auditor`, and `User`. A user's role controls the level of access they have to your account, both in the dashboard and through the management API.
|
||||
NetBird has eight user roles - `Owner`, `Admin`, `Network Admin`, `Billing Admin`, `Auditor`, `User`, and two roles scoped to [Agent Network](/agent-network), `Agent Network Admin` and `Usage Viewer`. A user's role controls the level of access they have to your account, both in the dashboard and through the management API.
|
||||
|
||||
## Permissions at a glance
|
||||
|
||||
@@ -31,6 +31,23 @@ Rows are grouped by what a `Network Admin` can do, from full access down to no a
|
||||
|
||||
<sup style={{fontSize: '0.9em', fontWeight: 'bold'}}>2</sup> A `Billing Admin`'s Settings access is limited to **Plans & Billing** and **Invoices**.
|
||||
|
||||
## Agent Network permissions
|
||||
|
||||
| Area | Owner | Admin | Auditor | Agent Network Admin | Usage Viewer | User |
|
||||
| --: | :--: | :--: | :--: | :--: | :--: | :--: |
|
||||
| Providers | ✅ | ✅ | 📖 | ✅ | 📖<sup style={{fontSize: '0.9em', fontWeight: 'bold'}}>3</sup> | ❌ |
|
||||
| Policies & Guardrails | ✅ | ✅ | 📖 | ✅ | ❌ | ❌ |
|
||||
| Global Limits | ✅ | ✅ | 📖 | ✅ | ❌ | ❌ |
|
||||
| Usage | ✅ | ✅ | 📖 | ✅ | 📖 | 📖<sup style={{fontSize: '0.9em', fontWeight: 'bold'}}>4</sup> |
|
||||
| Access Logs | ✅ | ✅ | 📖 | ✅ | 📖 | 📖<sup style={{fontSize: '0.9em', fontWeight: 'bold'}}>4</sup> |
|
||||
| Configuration | ✅ | ✅ | 📖 | ✅ | ❌ | ❌ |
|
||||
|
||||
`Network Admin` and `Billing Admin` have no Agent Network access beyond what every user gets.
|
||||
|
||||
<sup style={{fontSize: '0.9em', fontWeight: 'bold'}}>3</sup> A `Usage Viewer` sees the provider list with connection config redacted: no upstream URLs and no operator-supplied header values.
|
||||
|
||||
<sup style={{fontSize: '0.9em', fontWeight: 'bold'}}>4</sup> Every user, whatever their role, sees their own usage and their own requests on **Usage & Logs**.
|
||||
|
||||
## Owner
|
||||
The `Owner` has full access to the account and can manage every aspect of it. There can be only one account owner in NetBird. Owners are the only users who can delete the organization account - see [Delete NetBird account](/manage/settings/delete-account) for more.
|
||||
|
||||
@@ -49,8 +66,21 @@ An `Auditor` can read every configuration in the account but can't modify anythi
|
||||
## User
|
||||
A `User` has limited access: they can view the peers they own and other peers they're allowed to connect to.
|
||||
|
||||
## Agent Network Admin
|
||||
An `Agent Network Admin` has full control over Agent Network: providers, policies and guardrails, global limits, usage, access logs, and the configuration pages. They have read-only access to users, groups, peers, and account information, which they need to build policies. They have no access to any other part of the account, such as Control Center, Access Control, Network Routing, DNS, Setup Keys, or Reverse Proxy. The **Clusters** tab under Agent Network configuration stays hidden for this role because it requires Reverse Proxy permissions.
|
||||
|
||||
## Usage Viewer
|
||||
A `Usage Viewer` has read-only access to the Agent Network **Usage** overview and to the account-wide **Access Logs**. They can also read the provider list, with connection config redacted, and users, groups, and peers, which the filters and name columns rely on. They have no access to policies, guardrails, global limits, or Agent Network configuration.
|
||||
|
||||
<Warning>
|
||||
When [prompt collection](/agent-network/usage-and-logs/log-collection) is enabled, access logs contain the captured prompts and completions of every user. Granting `Usage Viewer` lets that user read other users' prompts.
|
||||
</Warning>
|
||||
|
||||
## Agent Network access for every user
|
||||
Any signed-in user, whatever their role, sees their own usage and their own requests on **Usage & Logs**. Once an Agent Network policy covers them, they also see the **Connect** page, which lists the providers and models their policies allow.
|
||||
|
||||
## Roles and the API
|
||||
Roles apply the same way whether a user works in the dashboard or through the [NetBird management API](/api) - a user's permissions over API resources match their role. Every role except `User` can create a personal access token that carries the same permissions as that user's role, so they can interact with the API programmatically.
|
||||
Roles apply the same way whether a user works in the dashboard or through the [NetBird management API](/api) - a user's permissions over API resources match their role. Every role except `User`, `Agent Network Admin`, and `Usage Viewer` can create a personal access token that carries the same permissions as that user's role, so they can interact with the API programmatically.
|
||||
|
||||
## Roles and identity provider sync
|
||||
<Note>
|
||||
@@ -62,7 +92,7 @@ To change a user's role, go to the `Team` tab, select the `Users` tab, and click
|
||||
<p>
|
||||
<img src="/docs-static/img/manage/team/user-tab-list.png" alt="user list in the Team tab" className="imagewrapper-big"/>
|
||||
</p>
|
||||
Select the desired role from the dropdown:
|
||||
Select the desired role from the dropdown. `Agent Network Admin` and `Usage Viewer` are under the **Agent Network** tab:
|
||||
<p>
|
||||
<img src="/docs-static/img/manage/team/user-update-role.png" alt="user role dropdown" className="imagewrapper-big"/>
|
||||
</p>
|
||||
|
||||
Reference in New Issue
Block a user