User Roles

Updated

NetBird has eight user roles - Owner, Admin, Network Admin, Billing Admin, Auditor, User, and two roles scoped to Agent Network, Agent Network Admin and Usage Viewer. A user's role controls the level of access they have to your account, both in the dashboard and through the management API.

Permissions at a glance

Rows are grouped by what a Network Admin can do, from full access down to no access.

AreaOwnerAdminNetwork AdminBilling AdminAuditorUser
Control Centerโœ…โœ…โœ…โŒ๐Ÿ“–โŒ
Access Controlโœ…โœ…โœ…โŒ๐Ÿ“–โŒ
Network Routingโœ…โœ…โœ…โŒ๐Ÿ“–โŒ
DNSโœ…โœ…โœ…โŒ๐Ÿ“–โŒ
Peersโœ…โœ…๐Ÿ“–โŒ๐Ÿ“–๐Ÿ“–1
Setup Keysโœ…โœ…๐Ÿ“–โŒ๐Ÿ“–โŒ
Teamโœ…โœ…๐Ÿ“–โŒ๐Ÿ“–โŒ
Activityโœ…โœ…๐Ÿ“–โŒ๐Ÿ“–โŒ
Settingsโœ…โœ…๐Ÿ“–โœ…2๐Ÿ“–โŒ
Reverse Proxyโœ…โœ…โŒโŒ๐Ÿ“–โŒ
Tenantsโœ…โœ…โŒโŒ๐Ÿ“–โŒ
Integrationsโœ…โœ…โŒโŒ๐Ÿ“–โŒ

Legend: โœ… = Full access ยท ๐Ÿ“– = Read only ยท โŒ = No access

1 A User can only see the peers they own and peers they're allowed to connect to.

2 A Billing Admin's Settings access is limited to Plans & Billing and Invoices.

Agent Network permissions

AreaOwnerAdminAuditorAgent Network AdminUsage ViewerUser
Providersโœ…โœ…๐Ÿ“–โœ…๐Ÿ“–3โŒ
Policies & Guardrailsโœ…โœ…๐Ÿ“–โœ…โŒโŒ
Global Limitsโœ…โœ…๐Ÿ“–โœ…โŒโŒ
Usageโœ…โœ…๐Ÿ“–โœ…๐Ÿ“–๐Ÿ“–4
Access Logsโœ…โœ…๐Ÿ“–โœ…๐Ÿ“–๐Ÿ“–4
Configurationโœ…โœ…๐Ÿ“–โœ…โŒโŒ

Network Admin and Billing Admin have no Agent Network access beyond what every user gets.

3 A Usage Viewer sees the provider list with connection config redacted: no upstream URLs and no operator-supplied header values.

4 Every user, whatever their role, sees their own usage and their own requests on Usage & Logs.

Owner

The Owner has full access to the account and can manage every aspect of it. There can be only one account owner in NetBird. Owners are the only users who can delete the organization account - see Delete NetBird account for more.

Admin

An Admin has full access to the account, with two exceptions: administrators can't delete or change the role of the Owner, and they can't delete the organization account.

Network Admin

A Network Admin fully manages network configuration - Control Center, Access Control, Network Routing, and DNS. They have read-only access to Peers, Setup Keys, Team, Activity, and Settings, and no access to Reverse Proxy, Tenants, or Integrations. A Network Admin can view setup keys but not create them, and can't invite users or create service users.

Billing Admin

A Billing Admin manages billing only. They can access Settings โ†’ Plans & Billing and Settings โ†’ Invoices, and have no access to any other part of the account.

Auditor

An Auditor can read every configuration in the account but can't modify anything.

User

A User has limited access: they can view the peers they own and other peers they're allowed to connect to.

Agent Network Admin

An Agent Network Admin has full control over Agent Network: providers, policies and guardrails, global limits, usage, access logs, and the configuration pages. They have read-only access to users, groups, peers, and account information, which they need to build policies. They have no access to any other part of the account, such as Control Center, Access Control, Network Routing, DNS, Setup Keys, or Reverse Proxy. The Clusters tab under Agent Network configuration stays hidden for this role because it requires Reverse Proxy permissions.

Usage Viewer

A Usage Viewer has read-only access to the Agent Network Usage overview and to the account-wide Access Logs. They can also read the provider list, with connection config redacted, and users, groups, and peers, which the filters and name columns rely on. They have no access to policies, guardrails, global limits, or Agent Network configuration.

Agent Network access for every user

Any signed-in user, whatever their role, sees their own usage and their own requests on Usage & Logs. Once an Agent Network policy covers them, they also see the Connect page, which lists the providers and models their policies allow.

Roles and the API

Roles apply the same way whether a user works in the dashboard or through the NetBird management API - a user's permissions over API resources match their role. Every role except User, Agent Network Admin, and Usage Viewer can create a personal access token that carries the same permissions as that user's role, so they can interact with the API programmatically.

Roles and identity provider sync

Assign a role

To change a user's role, go to the Team tab, select the Users tab, and click the user you want to update:

user list in the Team tab

Select the desired role from the dropdown. Agent Network Admin and Usage Viewer are under the Agent Network tab:

user role dropdown

Click the Save button to apply the change.

Get started