Varcio FinOps Copilot

Permission Catalogue

All 27 page permissions and all 69 action permissions, with what each governs.

Access is enforced in two independent server-side layers. See Access Control for how they compose.

Page permissions (27)

Each governs access to a module or family of modules, controlling both navigation and the underlying API routes.

PermissionCategoryGoverns
command_centerCoreApex and all eleven of its screens
overviewSpend & OptimizationOverview, Optimization, CEO View, AI Infrastructure, AI Provider Accounts
aws_accountsCoreCloud Accounts across all four providers
cloud_inventorySecurity & RiskInventory and FinSecOps
integrationsCoreIntegrations and Kubernetes
pr_cost_diffControls & GovernancePR Cost Review
approvalsControls & GovernanceApprovals
findingsSpend & OptimizationOpportunity Queue and Compliance
policiesControls & GovernancePolicies
intelligenceSpend & OptimizationIntelligence, Reports, Cost Center, Database Health, API Monitoring, Predictive Analytics, Cloud Playground, Deploy & Migration, CI/CD Control Tower
audit_logsControls & GovernanceAudit Logs
supportHelp & UpdatesSupport and Errors
settingsWorkspace & AccessSettings
organizationWorkspace & AccessOrganization, Workspace Setup, Org Analytics
membershipWorkspace & AccessMembership and Apex AI Credits
cloud_billingSpend & OptimizationCloud Billing
identityWorkspace & AccessIdentity & SSO
waste_schedulesControls & GovernanceWaste scheduling
tag_policiesControls & GovernanceTag Governance
spend_allocationControls & GovernanceCost Allocation
finops_maturitySpend & OptimizationFinOps Maturity
vendorsSpend & OptimizationVendor Hub and its sub-modules
resource_parkingControls & GovernanceResource Parking
unit_economicsSpend & OptimizationUnit Economics
ownershipControls & GovernanceOwnership
autopilotSpend & OptimizationAutopilot
ai_costSpend & OptimizationAI cost surfaces

Note the breadth of `intelligence`

A single permission governs nine modules. Granting it is a larger decision than it looks — review what it opens before assigning it broadly.

Action permissions (69)

Each governs a specific operation. A user may hold a page permission without holding the action permissions for operations on that page.

DomainActions
Cloud accountsaws_accounts.create, .delete, .verify_connection, .write_access_verify — and the identical four for azure_accounts, gcp_accounts, and oci_accounts (16 total)
AWS Organizationsaws_organizations.create, aws_organizations.assign_account
Inventoryinventory.scan
Integrationsintegrations.manage, .create_ticket, .run_alerts, .ingest_kubernetes, .execute_remediation
Infrastructure as codeiac.analyze
Spendspend.ingest_demo, spend.ingest_ce
Findingsfindings.update_status
Policiespolicies.create, .update, .delete
Budgetsbudgets.upsert
Approvalsapprovals.decide
Workspacesworkspaces.create
Authenticationauth.update_profile, auth.delete_account
Organizationorganization.manage_users
Intelligenceintelligence.ingest_telemetry, .waste_scan, .negotiate_commitments
Release intelligencerelease_intelligence.request_action
Cloud changescloud_changes.apply
Autopilotautopilot.config.manage, .rules.manage, .evaluate.run, .actions.review
Ownershipownership.teams.manage, .services.manage, .assignments.manage, .rules.manage, .sweep.run
Membershipmembership.manage
Cloud billingcloud_billing.dispute
SSOsso.configure
Waste scheduleswaste_schedules.create, .update, .delete, .execute
Tag policiestag_policies.create, .update, .delete
Spend allocationspend_allocation.create, .update, .delete
Vendorsvendors.create, .update, .archive, .manage_catalogs
Database healthdb_health.alert_rules.manage

The permissions to guard most carefully

These reach your cloud infrastructure or your money

Reserve these for the small number of people accountable for changes to the estate:

PermissionWhy it matters
approvals.decideApproves every gated change in the platform
integrations.execute_remediationExecutes changes against your cloud
autopilot.*Governs autonomous action
cloud_changes.applyApplies changes to live cloud state
intelligence.negotiate_commitmentsCommits real money to Savings Plans
*_accounts.write_access_verifyGrants the platform execution capability
membership.manageChanges the commercial relationship
sso.configureChanges how everyone authenticates

On this page