Role Access
Decide what each role in your organisation can see and change — which pages, at which level, and over which clusters and namespaces.
A role is a named set of permissions. Every user holds a role, and the role decides three things: which parts of KubeSense they can reach, whether they can only look or also change things there, and — for logs and traces — which clusters and namespaces they see data from.
Manage roles from Settings → Role Access. Assign them to people from Settings → Users.
Built-in roles
A new installation starts with two roles:
| Role | Starts with |
|---|---|
| Admin | Every module, at Editor |
| User | Logs, traces, infrastructure and RUM Events at Viewer; everything else off |
New modules added by an upgrade are granted to Admin and to nobody else, so a feature arrives closed and an administrator opens it per role. Create your own roles for anything in between.
Creating a role
Click Add Role Access.
- Name — up to 40 characters. This is what you pick from when assigning the role to a user.
- Description — optional; shown in the roles list.
- Data Scope — which clusters and namespaces the role sees traces and logs from. See Data scope.
- Modules — switch on each area the role may use, and choose its level.
Click Create. A role must have at least one module switched on; saving one with nothing enabled is refused, since it would grant nothing.
Viewer and Editor
Most modules take a level once switched on:
| Level | What it allows |
|---|---|
| Viewer | Open the page and read everything on it |
| Editor | Also create, edit and delete |
A Viewer still sees every control on a page; the ones that would change something are disabled, with a tooltip saying the role is read-only.
Some modules have no level, because there is nothing on them to change: Infrastructure, RUM Events, Audit Log and AI Chat. For those the switch alone is the whole decision.
note: The level is enforced by the API, not only by the page. A Viewer who calls the API directly — or through an API key or an AI agent — is refused the same way.
Data scope
The Traces and Logs cards scope what data the role can read, not just whether it can open the page. Each has its own switch and a picker over your clusters and their namespaces:
- Leave the picker at all to see every cluster and namespace — including ones added later.
- Pick a cluster to see all of its namespaces, again including future ones.
- Pick individual namespaces to see only those.
Data outside the scope is filtered out on the server: it does not appear in searches, charts or counts, and an API key or AI agent acting for the user sees exactly the same slice.
Traces and logs are scoped separately, so a role can, for example, read traces from every cluster but logs only from payments.
Modules
Modules that belong together are grouped under one card. The card's switch turns every module inside it on or off at once; each module inside can still be set on its own.
Standalone modules
| Module | Opens |
|---|---|
| Users | Settings → Users and Settings → Role Access. Editor invites users, changes their roles and edits roles. |
| Dashboard | Dashboards. Individual dashboards can be restricted further — see Dashboard Access. |
| Infrastructure | The Infrastructure pages, including cloud resources. View only. |
| SLO | Service levels. |
| Workflows | Workflows and their run history. Editor can publish a workflow, which may post to Slack or call an external endpoint. |
| Integrations | The platform integrations catalog — Confluence, Jira, Slack, custom MCP servers — and Cloud Integrations (AWS, Azure, GCP, Confluent, Kong, MongoDB Atlas). Editor connects, edits, tests and removes them. |
| Metrics | Metric stats, cardinality and exploration. Available to every role — no grant or level needed (see below). |
note: Metrics is open to everyone. It has no Viewer/Editor level and is granted to every role automatically, including roles added later, so you never switch it on.
note: Cloud Integrations (AWS, Azure, GCP and other cloud accounts) are part of the Integrations module, not General. A role needs Integrations to view or manage cloud provider connections.
Alerts
| Module | Opens |
|---|---|
| Manage Alert Rules | Alert rules and alert events |
| Notification Channels | Where alerts are delivered — Slack, Teams, webhooks |
| Maintenance Windows | Muting chosen rules or labels for a period |
| Alerts Admin | A maintenance window that mutes every alert (needs Maintenance Windows as well), and changing who may edit any alert rule, not only one's own (needs Manage Alert Rules as well). See Restricting who can edit a rule. |
warning: The Alerts card's switch turns Alerts Admin off with the rest, but never on. It mutes every page for everyone and overrides rule owners, so it is only granted by switching it on deliberately.
Settings
Each Settings tab is its own grant, so a role can be given exactly one.
| Module | Opens |
|---|---|
| General | Cost & Usage and Correlation Timeframe |
| Domain Management | Settings → Domain |
| Data Retention | Settings → Data Retention |
| Trace Filters | Settings → Trace Filters. Needs Traces as well — the rule form searches trace attributes. |
| Trace Filter Admin | Changing any trace filter rule and who may edit it, not only one's own. Needs Trace Filters at Editor as well. See Restricting who can change a rule. |
| Audit Log | Settings → Audit Logs. View only. |
The Settings card's switch never turns Trace Filter Admin on. It is granted to the Admin role on upgrade, and to other roles only by switching it on deliberately.
RUM
| Module | Opens |
|---|---|
| RUM Events | Real User Monitoring — sessions, views, errors. View only. |
| RUM Settings | Settings → RUM: registering applications and their SDK configuration |
Logs Management
The Logs explorer itself is covered by the Logs data-scope card above. These are the pages that manage logs:
| Module | Opens |
|---|---|
| Log Pipeline | Log pipelines and Settings → Reference Tables |
| Log Pipeline Admin | Changing any log pipeline and who may edit it, not only one's own. Needs Log Pipeline at Editor as well. See Restricting who can change a pipeline. |
| Log Metrics | Settings → Log Metrics — metrics generated from logs. Needs Logs as well, to preview the metric from a search. |
| Archived Logs | Searching logs that have moved to archive storage |
The Logs Management card's switch never turns Log Pipeline Admin on. It is granted to the Admin role on upgrade, and to other roles only by switching it on deliberately.
LLM
| Module | Opens |
|---|---|
| LLM Monitoring | LLM Observability — traces, dashboards, evaluations |
| LLM Settings | Managing LLM applications, their models and connections, and custom evaluators |
AI
| Module | Opens |
|---|---|
| Chat | Agent SRE chat. Conversations are private to each user. |
| Investigations | Agent SRE investigations. Viewer reads them; Editor starts and continues them. |
| Settings | Settings → Agent SRE — context, token limits |
note: Groups and modules appear only for features enabled on your installation. Indexed Attributes is granted to the Admin role on upgrade and cannot yet be granted to other roles from this form.
Assigning a role
Open Settings → Users, choose a user, and pick their role. The user needs no action on their side; their next request is answered under the new role. A page they already have open may need a refresh before its menus catch up.
Editing and deleting a role
Use the ⋯ menu on a row in the roles list:
- Edit — change anything, including the data scope. Changes apply to every user holding the role on their next request.
- Delete — refused while any user still holds the role. Move those users to another role first, then delete it. Deleting cannot be undone.
The list shows each role's Number of users and Last Edit, so you can see what a change will affect before you make it.
API keys
An API key never reaches further than its creator. Its scopes are chosen from what the creator's role can already access, and the role's level and data scope still apply on top. See Logs & Traces API.
Audit
Creating, editing and deleting a role are recorded in Settings → Audit Logs — who made the change, and to which role.