Kubesense

Role Access

Decide what each role in your organisation can see and change — which pages, at which level, and over which clusters and namespaces.

A role is a named set of permissions. Every user holds a role, and the role decides three things: which parts of KubeSense they can reach, whether they can only look or also change things there, and — for logs and traces — which clusters and namespaces they see data from.

Manage roles from Settings → Role Access. Assign them to people from Settings → Users.

Built-in roles

A new installation starts with two roles:

RoleStarts with
AdminEvery module, at Editor
UserLogs, traces, infrastructure and RUM Events at Viewer; everything else off

New modules added by an upgrade are granted to Admin and to nobody else, so a feature arrives closed and an administrator opens it per role. Create your own roles for anything in between.

Creating a role

Click Add Role Access.

  1. Name — up to 40 characters. This is what you pick from when assigning the role to a user.
  2. Description — optional; shown in the roles list.
  3. Data Scope — which clusters and namespaces the role sees traces and logs from. See Data scope.
  4. Modules — switch on each area the role may use, and choose its level.

Click Create. A role must have at least one module switched on; saving one with nothing enabled is refused, since it would grant nothing.

Viewer and Editor

Most modules take a level once switched on:

LevelWhat it allows
ViewerOpen the page and read everything on it
EditorAlso create, edit and delete

A Viewer still sees every control on a page; the ones that would change something are disabled, with a tooltip saying the role is read-only.

Some modules have no level, because there is nothing on them to change: Infrastructure, RUM Events, Audit Log and AI Chat. For those the switch alone is the whole decision.

note: The level is enforced by the API, not only by the page. A Viewer who calls the API directly — or through an API key or an AI agent — is refused the same way.

Data scope

The Traces and Logs cards scope what data the role can read, not just whether it can open the page. Each has its own switch and a picker over your clusters and their namespaces:

  • Leave the picker at all to see every cluster and namespace — including ones added later.
  • Pick a cluster to see all of its namespaces, again including future ones.
  • Pick individual namespaces to see only those.

Data outside the scope is filtered out on the server: it does not appear in searches, charts or counts, and an API key or AI agent acting for the user sees exactly the same slice.

Traces and logs are scoped separately, so a role can, for example, read traces from every cluster but logs only from payments.

Modules

Modules that belong together are grouped under one card. The card's switch turns every module inside it on or off at once; each module inside can still be set on its own.

Standalone modules

ModuleOpens
UsersSettings → Users and Settings → Role Access. Editor invites users, changes their roles and edits roles.
DashboardDashboards. Individual dashboards can be restricted further — see Dashboard Access.
InfrastructureThe Infrastructure pages, including cloud resources. View only.
SLOService levels.
WorkflowsWorkflows and their run history. Editor can publish a workflow, which may post to Slack or call an external endpoint.
IntegrationsThe platform integrations catalog — Confluence, Jira, Slack, custom MCP servers — and Cloud Integrations (AWS, Azure, GCP, Confluent, Kong, MongoDB Atlas). Editor connects, edits, tests and removes them.
MetricsMetric stats, cardinality and exploration. Available to every role — no grant or level needed (see below).

note: Metrics is open to everyone. It has no Viewer/Editor level and is granted to every role automatically, including roles added later, so you never switch it on.

note: Cloud Integrations (AWS, Azure, GCP and other cloud accounts) are part of the Integrations module, not General. A role needs Integrations to view or manage cloud provider connections.

Alerts

ModuleOpens
Manage Alert RulesAlert rules and alert events
Notification ChannelsWhere alerts are delivered — Slack, Teams, webhooks
Maintenance WindowsMuting chosen rules or labels for a period
Alerts AdminA maintenance window that mutes every alert (needs Maintenance Windows as well), and changing who may edit any alert rule, not only one's own (needs Manage Alert Rules as well). See Restricting who can edit a rule.

warning: The Alerts card's switch turns Alerts Admin off with the rest, but never on. It mutes every page for everyone and overrides rule owners, so it is only granted by switching it on deliberately.

Settings

Each Settings tab is its own grant, so a role can be given exactly one.

ModuleOpens
GeneralCost & Usage and Correlation Timeframe
Domain ManagementSettings → Domain
Data RetentionSettings → Data Retention
Trace FiltersSettings → Trace Filters. Needs Traces as well — the rule form searches trace attributes.
Trace Filter AdminChanging any trace filter rule and who may edit it, not only one's own. Needs Trace Filters at Editor as well. See Restricting who can change a rule.
Audit LogSettings → Audit Logs. View only.

The Settings card's switch never turns Trace Filter Admin on. It is granted to the Admin role on upgrade, and to other roles only by switching it on deliberately.

RUM

ModuleOpens
RUM EventsReal User Monitoring — sessions, views, errors. View only.
RUM SettingsSettings → RUM: registering applications and their SDK configuration

Logs Management

The Logs explorer itself is covered by the Logs data-scope card above. These are the pages that manage logs:

ModuleOpens
Log PipelineLog pipelines and Settings → Reference Tables
Log Pipeline AdminChanging any log pipeline and who may edit it, not only one's own. Needs Log Pipeline at Editor as well. See Restricting who can change a pipeline.
Log MetricsSettings → Log Metrics — metrics generated from logs. Needs Logs as well, to preview the metric from a search.
Archived LogsSearching logs that have moved to archive storage

The Logs Management card's switch never turns Log Pipeline Admin on. It is granted to the Admin role on upgrade, and to other roles only by switching it on deliberately.

LLM

ModuleOpens
LLM MonitoringLLM Observability — traces, dashboards, evaluations
LLM SettingsManaging LLM applications, their models and connections, and custom evaluators

AI

ModuleOpens
ChatAgent SRE chat. Conversations are private to each user.
InvestigationsAgent SRE investigations. Viewer reads them; Editor starts and continues them.
SettingsSettings → Agent SRE — context, token limits

note: Groups and modules appear only for features enabled on your installation. Indexed Attributes is granted to the Admin role on upgrade and cannot yet be granted to other roles from this form.

Assigning a role

Open Settings → Users, choose a user, and pick their role. The user needs no action on their side; their next request is answered under the new role. A page they already have open may need a refresh before its menus catch up.

Editing and deleting a role

Use the ⋯ menu on a row in the roles list:

  • Edit — change anything, including the data scope. Changes apply to every user holding the role on their next request.
  • Delete — refused while any user still holds the role. Move those users to another role first, then delete it. Deleting cannot be undone.

The list shows each role's Number of users and Last Edit, so you can see what a change will affect before you make it.

API keys

An API key never reaches further than its creator. Its scopes are chosen from what the creator's role can already access, and the role's level and data scope still apply on top. See Logs & Traces API.

Audit

Creating, editing and deleting a role are recorded in Settings → Audit Logs — who made the change, and to which role.