olOpsLyft Docs

Security and data access

What OpsLyft can read, what it can never do, and how access is scoped for each provider.

OpsLyft is read-only by design. It can see billing and usage data, and resource metadata where you allow it. It can't change, stop, or delete anything in your accounts.

Access by provider

Each connection uses the least access needed to read cost and usage.

ProviderAccess OpsLyft usesWhat it reads
AWSRead-only IAM role OpsLyftReadOnly created by a CloudFormation stackCUR 2.0 billing export, resource metadata, utilisation metrics
AzureCost Management Reader on the billing scopeCost Management exports
Google CloudRead-only service account on the billing export datasetBigQuery detailed usage export
SnowflakeRead-only monitor userACCOUNT_USAGE views
DatabricksSELECT on Unity Catalog system.billingSystem billing tables
KubernetesIn-cluster cost agent installed with HelmNamespace and workload usage
OpenAIAdmin usage keyUsage and cost endpoints
AnthropicAdmin usage keyUsage and cost reports

Business data

When you connect a dataset, OpsLyft requests the least access needed to read it. Nothing is written back to your database, bucket, sheet, or endpoint.

Actions that change things

OpsLyft suggests changes; people make them. When an opportunity has a Remediate plan, each step is either run by you or handed to a coding agent you control. Iris always asks before it runs an action in the app, such as saving a view or opening a ticket.

Workspace identifiers

Settings → General → Identifiers shows your organisation ID, home region, creation date, and plan. These are read-only and safe to paste into a support ticket.

On this page