---
title: Permissions and roles
source: https://docs.newrelic.com/docs/cci/configure-cci/cci-permissions
---

New Relic's standard authorization system controls access to Cloud Cost Intelligence surfaces (Settings, Integrations, and Custom Facets). It splits access into read (view configuration) and write (create, update, delete), per account, not organization-wide.

## Default access [#default-access]

All users with account access get view-only access by default.

Only an Organization Admin can grant modify, edit, or delete access — to themselves, to other individual users, or to a role.

## Grant modify access [#grant-modify-access]

An Organization Admin grants CCI write access through a [custom role](https://docs.newrelic.com/docs/accounts/accounts-billing/new-relic-one-user-management/account-user-mgmt-tutorial/#roles). Two options are available:

### Option 1: Add CCI permissions to an existing custom role [#option-existing-role]

If a custom role already exists for a team (for example, a "FinOps" role), add the CCI write capabilities to it. Everyone already assigned that role automatically gains CCI write access. No per-user reassignment is needed.

### Option 2: Create a dedicated custom role for CCI [#option-new-role]

Create a custom role containing only the CCI modify capabilities (Settings, Integrations, Custom Facets), then assign it to the specific users, groups, or yourself who need it. Use this option to keep CCI administration separate from any other role's responsibilities.

## Related topics [#related-topics]

[User management concepts](https://docs.newrelic.com/docs/accounts/accounts-billing/new-relic-one-user-management/user-management-concepts)

Understand roles, groups, and capabilities in New Relic

[Tutorial: Add and manage users](https://docs.newrelic.com/docs/accounts/accounts-billing/new-relic-one-user-management/account-user-mgmt-tutorial)

Step-by-step guide to creating and assigning custom roles
