# Role-based access control for cloud cost | ZopNight

> Built-in roles, custom roles scoped to individual resources, team access that follows ownership, and Cloud IAM Import from AWS, Google Cloud and Azure.

Source: https://zop.dev/zopnight/access-control

---

_Least privilege, by default_

## Access scoped to each resource.

Three built-in roles, custom roles scoped down to individual resources, and team access that follows the resources a team owns. Bring your cloud's own access model with you rather than rebuilding it by hand.

- 3 — built-in roles, plus custom
- Per resource — scoping for any role
- 0 — admin rights copied from cloud IAM
- SAML — single sign-on

Free to start. No card. The playground just needs your work email.

## Access that follows ownership.

Scope follows the team, not a spreadsheet.

- 01. Start from a role — Admin, Editor or Viewer cover most people. Editors change resources; only Admins manage the account itself.
- 02. Scope it down — Custom roles narrow any permission to named resources. A contractor can manage the schedules for one set of named resources and see nothing else.
- 03. Let teams inherit — Team members get their role's permissions, scoped to the resources the team owns.
- 04. Cloud IAM Import — Pull IAM principals from AWS, Google Cloud and Azure as suggested users, teams and roles. Nothing is written until you review the preview and click Apply.

## Least privilege, without the spreadsheet.

Enforced in one place, for people and agents alike.

- Enforcement: Every API call is checked at the gateway against the permission it needs. There is no way around it, including for AI agents over MCP.
- Scoping: Each permission can cover all resources, none, or a named list. Every service filters its data to that scope before returning anything.
- Cloud IAM Import: Suggestions only. Admin rights are never granted automatically, even from AWS AdministratorAccess, Google Cloud Owner or Azure Owner, and it never writes to your cloud IAM.
- Sign-in: Google, GitHub or email, and SAML single sign-on, set up with the ZopNight team for your email domain.

## Give everyone access. Exactly enough.

Invite your team and scope each person in a few clicks, or start from your cloud's IAM.

[object Object]
