Security and data access
What OpsLyft can read, what it can never do, and how access is scoped for each provider.
OpsLyft is read-only by design. It can see billing and usage data, and resource metadata where you allow it. It can't change, stop, or delete anything in your accounts.
Access by provider
Each connection uses the least access needed to read cost and usage.
| Provider | Access OpsLyft uses | What it reads |
|---|---|---|
| AWS | Read-only IAM role OpsLyftReadOnly created by a CloudFormation stack | CUR 2.0 billing export, resource metadata, utilisation metrics |
| Azure | Cost Management Reader on the billing scope | Cost Management exports |
| Google Cloud | Read-only service account on the billing export dataset | BigQuery detailed usage export |
| Snowflake | Read-only monitor user | ACCOUNT_USAGE views |
| Databricks | SELECT on Unity Catalog system.billing | System billing tables |
| Kubernetes | In-cluster cost agent installed with Helm | Namespace and workload usage |
| OpenAI | Admin usage key | Usage and cost endpoints |
| Anthropic | Admin usage key | Usage and cost reports |
Business data
When you connect a dataset, OpsLyft requests the least access needed to read it. Nothing is written back to your database, bucket, sheet, or endpoint.
Actions that change things
OpsLyft suggests changes; people make them. When an opportunity has a Remediate plan, each step is either run by you or handed to a coding agent you control. Iris always asks before it runs an action in the app, such as saving a view or opening a ticket.
Workspace identifiers
Settings → General → Identifiers shows your organisation ID, home region, creation date, and plan. These are read-only and safe to paste into a support ticket.