Overview
This article describes the user management capabilities in Cost Analyzer for a Turbo360 account using Email authentication. Account owner and Owner roles can control who can access the module and what they can do inside it — adding users by email invitation, assigning roles at the module level or scoped to specific Cost management groups, and removing users when access is no longer needed.
If your Turbo360 account uses Microsoft Entra ID for sign-in instead, see the Microsoft Entra ID article — user provisioning and role assignment work differently for that authentication mode.
Business value
Centralized user management lets you enforce least-privilege access across Cost Analyzer — granting broad access to administrators while restricting contractors or specific teams to only the Cost management groups they need, reducing the risk of unintended cost data exposure.
Prerequisites
Your Turbo360 account must use Email authentication. You also need the appropriate role in Cost Analyzer to manage users — see Required permissions below.
Required permissions
| Role | Access |
|---|---|
| Account owner | Full access — add, update, and remove users |
| Owner | Full access — add, update, and remove users |
| Custom role with Manage users enabled | Full access — add, update, and remove users |
| Custom role without Manage users | No access to user management |
To perform user management operations, you must have the Account owner or Owner role, or a custom role with the Manage users permission enabled. Account owners can enable this under Specify management permissions when configuring a custom role.
Besides the built-in Account owner and Owner roles, a custom role can also be granted user management access. Under Roles > Add role > Specify management permissions, enabling Manage users lets that role add or remove users and update user permissions. It does not grant the ability to create, edit, or delete roles — that stays limited to Account owner and Owner.
How it works
Cost Analyzer supports two ways to assign roles to a user:
- Direct role assignment — assigns a role for the entire module. For example, assigning Reader directly gives a user complete read access to all views, monitors, and optimization schedules in Cost Analyzer.
- Specified access — assigns different roles to different Cost management groups. For example, if your organization has separate Production and Development Cost management groups, you can give a contractor Reader access to only the Development group by choosing that group and assigning a role scoped to it.
Users who are already part of Turbo360 — as members of another module, or with no module permission yet — can be added to Cost Analyzer from the Existing user tab instead of sending a new invitation.
Steps
Use the following steps to add, manage, and remove users in Cost Analyzer. Navigate to Cost Analyzer > User management > Users tab to get started.
Add a user
Adding a user sends an email invitation that grants them access to Cost Analyzer once accepted.
- Click Add user in the Users tab.
- Enter the user's name and email address.
- Assign a role — either as a direct role or with specified access to Cost management groups.
- Click Add.
An activation link is sent to the user's email address.
The activation link is valid for 3 days. After it expires, the Account owner / Owner must resend the activation email.
Update user permissions
Updating permissions lets you change a user's role scope — for example, switching from direct access to specified access, or restricting a user to a different set of groups.
- Navigate to the User management section of the module.
- Click Edit permission in the Actions column next to the user.
- Update the role — either as a direct role or with specified access.
- Click Update.
To update permissions for multiple users at once:
- Select the users whose roles you want to update.
- Click Edit permission above the user list.
- Assign a role — either as a direct role or with specified access.
- Click Update.
Only users who have direct access to a Cost management group can have that access revoked from the group's Users widget.
Create, edit, or delete a role
Managing roles lets you define custom permission sets, rather than relying only on the built-in Owner, Contributor, and Reader roles. Only Account owner and Owner can perform this — a custom role with Manage users enabled cannot create, edit, or delete roles.
- Go to the Roles tab in the User management section.
- Select Add role to create a new custom role, or select an existing role to edit it.
- Configure account, management, feature, and optimization tab permissions for the role.
- Save the role. To remove a role that's no longer needed, delete it from the Roles list.
Remove a user
Removing a user revokes their access to Cost Analyzer. The user remains in Turbo360's directory and can be re-added later.
- To remove a single user, click Remove user in the Actions column.
- To remove multiple users, select them and click Remove above the list.
A user removed from Cost Analyzer still exists in Turbo360's directory. To remove them from Turbo360 entirely, navigate to Settings > Users and select Remove user.
Permission behavior
- Account owner / Owner — can add users, remove users, edit any user's role assignment, and create, edit, or delete roles, either directly across the module or scoped to specific Cost management groups.
- Custom role with Manage users enabled — can add users, remove users, and update user permissions, but cannot create, edit, or delete roles — that remains exclusive to Account owner and Owner.
- Users with Direct role assignment — inherit that role's permissions across the entire module; without Manage users enabled, they cannot manage other users' access.
- Users with Specified access — only see and act within the Cost management groups they've been explicitly granted, at the role level assigned for each group.
Example scenario
An organization has two Cost management groups: Production and Development. A contractor should only work with Development-related cost data. Instead of a Direct role assignment (which would apply module-wide), the Account owner assigns the contractor Specified access, selecting only the Development group and assigning the Reader role for that group. The contractor can now view Development's views, monitors, and optimization schedules, but has no visibility into Production. When the engagement ends, the owner removes the user from the module.
Limitations
- This article applies only to Turbo360 accounts using Email authentication. Accounts using Microsoft Entra ID follow a different user management flow.
- A user removed from Cost Analyzer still exists in Turbo360's directory and retains membership in other modules until an Account owner removes them completely from Settings > Users.
- Creating, editing, and deleting roles is restricted to Account owner and Owner — this cannot be delegated via the Manage users permission.
Troubleshooting
-
Activation email not received
Cause: The email may have been filtered as spam, or the address was entered incorrectly.
Fix: Ask the user to check their spam folder. If the address is incorrect, remove the user and re-add them with the correct address. If the link has expired (after 3 days), resend the activation email from the user list. -
Cannot see the Add user option
Cause: Your role does not have permission to manage users.
Fix: Only users with the Account owner, Owner role, or a custom role with Manage users enabled can add users. Contact your account owner to request the appropriate access. -
User with Manage users can't create, edit, or delete a role
Cause: Manage users only grants control over users and their role assignments — it doesn't extend to managing roles themselves.
Fix: Ask an Account owner or Owner to create, edit, or delete the role; this can't be delegated to a custom role.