Refer to Manage cloud users for instructions on assigning organization roles.ClickHouse has four organization level roles available for user management. Only the admin role has default access to services. All other roles must be combined with service level roles to interact with services.
Role
Description
Admin
Perform all administrative activities for an organization and control all settings. This role is assigned to the first user in the organization by default and automatically has Service Admin permissions on all services.
Billing
View usage and invoices, and manage payment methods.
Org API reader
API permissions to manage organization level settings and users, no service access.
Member
Sign-in only with the ability to manage personal profile settings. Assigned to SAML SSO users by default.
Refer to Manage cloud users for instructions on assigning service roles.Service permissions must be explicitly granted by an admin to users with roles other than the admin role. The service admin role is pre-configured with SQL console admin access, but may be modified to reduce or remove permissions.
Role
Description
Service reader
View services and settings.
Service admin
Manage service settings.
Service API reader
API permissions to read service settings for all services.
Service API admin
API permissions to manage service settings for all services.
Manage ClickPipes integration and related settings. Accessing the Data Sources tab currently requires control-plane:service:manage (“Manage and Delete Selected Services”).