Users and Roles

Learn how user roles work in Ternary, including role definitions, permission differences, and which roles are best suited for administrators, power users, and MSPs.

Ternary uses role-based access control to define what users can view, create, edit, or manage within a tenant. Each role is designed to align with a specific level of responsibility, ranging from read-only access to full tenant or multi-tenant administration.

There are five supported user roles. Permissions vary by action type, such as creating resources, viewing data, updating configurations, or managing users and integrations.

What user roles are supported by Ternary?

RoleDescription
Partner AdminSpecial role for Managed Service Providers (MSPs) to access multiple customer tenants, including viewing, configuring, and managing them.
Tenant AdminFull control over the tenant, including user management, integrations, and advanced settings.
Full Access UserAdvanced permissions to create, edit, and manage most resources without tenant-level administration.
Basic UserStandard role for creating and managing dashboards, budgets, reports, and viewing most data.
Limited UserEntry-level role focused on viewing data and creating basic items like reports and dashboards.

How do role permissions differ?

Permissions in Ternary are grouped by action type. Each section below outlines and compares which roles can perform specific actions:

Create actions

PermissionsLimited UserBasic UserFull Access UserTenant AdminPartner Admin
BudgetsYYYYY
Case & Case CommentsYYYYY
DashboardYYYYY
ReportYYYYY
Resource SubscriptionYYYYY
Savings OpportunityYYYYY
Alert RuleNYYYY
Cost Compare BillNYYYY
Ramp PlanNYYYY
Custom Labels & MetricsNNYYY
Label Grouping Rules & PreferencesNNYYY
Data IntegrationNNNYY
User & User Group ConfigurationsNNNYY
Kubernetes Pod LabelsNNNYY

View (Read) actions

PermissionsLimited UserBasic UserFull Access UserTenant AdminPartner Admin
BudgetsYYYYY
CasesNYYYY
DashboardsYYYYY
Reports & Report DataYYYYY
Resource SubscriptionsYYYYY
RecommendationsYYYYY
Savings OpportunitiesYYYYY
Cost Alerts (Anomalies)YYYYY
Ramp PlansNYYYY
Label Map & PreferencesYYYYY
Reallocations & JobsNYYYY
Data IntegrationsYYYYY
Kubernetes Pod LabelsNNYYY
Roles & User RolesNNNYY

Update (Edit) actions

PermissionsLimited UserBasic UserFull Access UserTenant AdminPartner Admin
Resource SubscriptionsYYYYY
BudgetsNYYYY
CasesNYYYY
DashboardsNYYYY
ReportsNYYYY
RecommendationsNYYYY
Alert RulesNYYYY
Ramp PlansNYYYY
Label Grouping Rules & PreferencesNNYYY
Savings OpportunitiesNNYYY
ReallocationsNYYYY
Measure PreferencesNNYYY
Tenant-wide SettingsNNNYY
User Roles & Group ConfigsNNNYY

Delete actions

PermissionsLimited UserBasic UserFull Access UserTenant AdminPartner Admin
Resource SubscriptionsYYYYY
BudgetsNYYYY
ReportsNNYYY
Ramp PlansNNYYY
Label Grouping RulesNNYYY
Custom Labels & MetricsNNYYY
Savings OpportunitiesNNYYY
ReallocationsNNYYY
Kubernetes Pod LabelsNNNYY
Data IntegrationsNNNYY
User Group ConfigurationsNNNYY

Special actions

PermissionsLimited UserBasic UserFull Access UserTenant AdminPartner Admin
Generate Cost Compare reportNYYYY
View Committed Use pageNYYYY
Trigger reallocationNNYYY
Grant/revoke tenant accessNNNYY

Role summaries

The following summaries describe the intended use and access boundaries for each Ternary user role:

Limited User: Intended for team members who primarily need visibility into cost data.

  • View dashboards, reports, and core cost information
  • Create basic items such as reports and budgets

Basic User: Designed for users actively managing cost tracking and reporting.

  • All Limited User capabilities
  • Create and edit budgets, dashboards, and ramp plans
  • View recommendations and run cost comparisons

Full Access User: Best suited for power users handling advanced FinOps workflows.

  • All Basic User capabilities
  • Manage custom labels, metrics, reallocations, and advanced reporting tools
  • Trigger reallocations and manage measure preferences

Tenant Admin: For administrators responsible for the entire tenant configuration.

  • All Full Access User capabilities
  • Full control over integrations, Kubernetes labels, and user roles
  • Grant or revoke access and manage tenant-wide settings

Partner Admin: For managed service providers (MSPs) operating across multiple customer tenants.

  • Cross-tenant visibility into usage, costs, and configurations
  • Ability to configure, update, and manage customer tenants
  • Intended for MSPs supporting multiple customers

Role

Scope

Best for

Limited User

Single tenant

New team members who need to view data and run simple reports.

Basic User

Single tenant

Managing budgets, dashboards, and reports.

Full Access User

Single tenant

Power users who need advanced optimization and reporting control.

Tenant Admin

Single tenant

Full administration and user management.

Partner Admin

MSP Parent Tenant and all Child Tenants

Cross-tenant management, reporting, and support.