Document cost and budget visibility for non-billing users - #7273
Conversation
Organization members with resource-scoped roles (Admin, Editor, Viewer) can now view usage, costs, and budgets for the hosted deployments, serverless projects, and connected clusters they have access to, without needing Billing admin or Organization owner rights. This updates the three affected pages to describe who can see and manage billing data under the new access model, while keeping organization-wide financial data (credit balance, billing history, invoices, and organization-scoped budgets) owner/admin-only as before. Refs elastic/platform-billing#7643 (internal tracking issue). Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
Elastic Docs AI PR menuCheck the box to run an AI review for this pull request.
Powered by GitHub Agentic Workflows and docs-actions. For more information, reach out to the docs team. |
✅ Elastic Docs Style Checker (Vale)No issues found on modified lines! The Vale linter checks documentation changes against the Elastic Docs style guide. To use Vale locally or report issues, refer to Elastic style guide for Vale. |
Members with a connected cluster access role also gain usage/cost and budget visibility for the connected clusters in their scope, under the same Expanded Non-Billing User Access model already documented for cloud resource access roles. This adds the parallel note that was missing from the Connected cluster access roles section. Refs elastic/platform-billing#7643 (internal tracking issue). Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
There was a problem hiding this comment.
Pull request overview
Documents expanded visibility for usage/costs and budget management for non-billing users who already have resource-scoped access (cloud resource access roles and connected cluster access roles), while clarifying that organization-wide financial data remains restricted.
Changes:
- Adds role-based “who can see what” guidance for the Usage page, including a note about org-wide financial data remaining restricted.
- Clarifies how cloud resource access roles and connected cluster access roles relate to usage/cost visibility and budget management.
- Defines who can create/view/manage budgets depending on whether the budget scope is organization-wide or resource-scoped.
Reviewed changes
Copilot reviewed 3 out of 3 changed files in this pull request and generated 4 comments.
| File | Description |
|---|---|
| deploy-manage/users-roles/cloud-organization/user-roles.md | Adds references that resource-scoped roles also grant usage/cost visibility and budget actions within scope. |
| deploy-manage/cloud-organization/billing/monitor-analyze-usage.md | Adds a role-based visibility breakdown for Usage plus an org-wide-financial-data restriction note. |
| deploy-manage/cloud-organization/billing/manage-billing-notifications.md | Clarifies permissions to create/view/manage budgets based on budget scope. |
💡 Add Copilot custom instructions for smarter, more guided reviews. Learn how to get started.
There was a problem hiding this comment.
Docs review summary
Focus areas
- Style and clarity: One role-name styling inconsistency in the new note (inline comment). Otherwise the new prose is clear and well-structured.
- Jargon: No unexplained jargon introduced.
- Frontmatter and applies_to: No changes; existing frontmatter is intact.
- Content type fit: Changed sections fit naturally into the existing how-to pages.
- Parent issue satisfaction: Satisfied. All three deliverables from the PR description are present —
user-roles.mdadds billing-visibility notes for cloud resource and connected cluster access roles;monitor-analyze-usage.mdadds the who-can-view breakdown, the full-history note, and the org-wide-only callout;manage-billing-notifications.mdclarifies budget scope and role requirements.
Nits
monitor-analyze-usage.mdline 30: "its full available cost history" is slightly redundant — consider "its complete cost history" or "all available cost history".- Vale flags
**Billing > Usage**(line 35) and**Organization** > **Members**(user-roles.md line 32) should use→not>, but both are pre-existing lines not touched by this PR.
Generated by Docs review agent for issue #7273 · 29.5 AIC · ⌖ 4.7 AIC · ⊞ 10.7K
Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>
Rephrase the Cloud resource budget bullet to separate the requirements for viewing from those for creating, editing, or deleting, and note that a budget's scope can include connected clusters. Remove the "Admin or Editor" role examples, which don't apply to connected cluster access roles (Admin and Viewer only, no Editor). Addresses a Copilot review comment on elastic#7273. Refs elastic/platform-billing#7643 (internal tracking issue). Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
…Usage page The visibility bullet said "a cloud resource access role, such as Admin, Editor, or Viewer", but cloud resource access roles cover only hosted deployments and serverless projects. Connected clusters are governed by connected cluster access roles (a separate category with Admin and Viewer only, no Editor). Rewrite to name both role categories without listing role names, so the statement is accurate for both. Addresses a Copilot review comment on elastic#7273. Refs elastic/platform-billing#7643 (internal tracking issue). Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
"full available cost history" is slightly redundant — "complete cost history" conveys the same meaning more concisely. Refs elastic/platform-billing#7643 (internal tracking issue). Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
The important callout directed all readers to check invoices in billing history for the exact amount owed, but billing history and invoices are accessible only to organization owners and billing admins — not to members with resource-scoped roles who can now also reach the Usage page. Add a role condition so the instruction targets only the users who can actually follow it. Addresses a Copilot review comment on elastic#7273. Refs elastic/platform-billing#7643 (internal tracking issue). Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
Co-authored-by: Copilot Autofix powered by AI <175728472+Copilot@users.noreply.github.com>
Co-authored-by: Copilot Autofix powered by AI <175728472+Copilot@users.noreply.github.com>
"view access" and "manage access" were coined only in this paragraph and
not defined elsewhere in the doc set. Rephrase to verb phrases ("need to
be able to view/manage every resource in its scope") and add a link to
user-roles.md to give readers a path to role definitions.
Specific role names (Admin/Editor/Viewer) are intentionally omitted:
connected cluster access roles have only Admin and Viewer (no Editor),
and user-roles.md itself describes billing actions in terms of level of
access rather than enumerating roles per operation.
Addresses a Copilot review comment on elastic#7273.
Refs elastic/platform-billing#7643 (internal tracking issue).
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
Co-authored-by: Copilot Autofix powered by AI <175728472+Copilot@users.noreply.github.com>
Co-authored-by: Copilot Autofix powered by AI <175728472+Copilot@users.noreply.github.com>
Co-authored-by: Copilot Autofix powered by AI <175728472+Copilot@users.noreply.github.com>
Co-authored-by: Copilot Autofix powered by AI <175728472+Copilot@users.noreply.github.com>
The opening list on the Usage page presented the prepaid credit total without a visibility qualifier, implying it is visible to all users. In practice, credit balance information is an organization-wide financial detail accessible only to users with the Organization owner or Billing admin role — consistent with the note at the bottom of the page. Now that resource-scoped roles can reach the Usage page, omitting the qualifier could mislead non-billing users into expecting credit data they cannot see. Add a parenthetical scope note to align this item with the existing note. Addresses a Copilot review comment on elastic#7273. Refs elastic/platform-billing#7643 (internal tracking issue). Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
|
@elastic/admin-docs Could I have your review on this PR? Thanks! |
shainaraskas
left a comment
There was a problem hiding this comment.
very nice contribution - thank you! A couple of notes for clarity, organization, and focus
| :::{note} | ||
| Organization-wide financial details — such as your credit balance, [billing history](/deploy-manage/cloud-organization/billing/view-billing-history.md), and invoices — remain available only to users with the **Organization owner** or **Billing admin** role. | ||
| ::: No newline at end of file |
There was a problem hiding this comment.
this page is about usage monitoring, so this note feels out of place. I think that nothing that is present on this page would give the impression that users with other roles will be given access to financial details. It probably makes more sense to say who has access to those surfaces on the docs for those surfaces:
https://www.elastic.co/docs/deploy-manage/cloud-organization/billing/view-billing-history
https://www.elastic.co/docs/deploy-manage/cloud-organization/billing/ecu#view-available-credits
There was a problem hiding this comment.
@shainaraskas Thank you for this feedback and for all your other comments/suggestions. They are very helpful.
Regarding the "out of place" issue, you are right. So, I pushed 5e3cdb9 and a9766c6. What do you think?
I've received approval, but just to be sure, I'll wait a little while before merging. :)
Co-authored-by: shainaraskas <58563081+shainaraskas@users.noreply.github.com>
Per review feedback (r3633295750), the trailing note on the usage monitoring page — "Organization-wide financial details remain available only to Organization owner / Billing admin" — is out of place there: the page already scopes credits and invoices inline, and billing history/credits are not primary subjects of the usage page. Removes the note from monitor-analyze-usage.md and places equivalent access-scope notes on the two surfaces the note was describing: - view-billing-history.md: note that billing history requires Organization owner or Billing admin role - ecu.md (View available credits section): note that available credits require Organization owner or Billing admin role Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
Both ecu.md and view-billing-history.md now follow the same pattern:
intro sentence → :::{note} (access restriction) → subsequent content.
Standardize the verb to "visible only to" in both notes for consistency.
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
Summary
Documents the Expanded Non-Billing User Access change: organization members with a cloud resource access role or a connected cluster access role can now view usage, costs, and manage budgets for the hosted deployments, serverless projects, and connected clusters they already have access to — without needing Billing admin or Organization owner rights. Organization-wide financial data (credit balance, billing history, invoices, and organization-scoped budgets) remains owner/admin-only, unchanged.
deploy-manage/users-roles/cloud-organization/user-roles.md: notes that both cloud resource access roles and connected cluster access roles also grant usage/cost/budget visibility for resources in their scope, linking to the two billing pages below.deploy-manage/cloud-organization/billing/monitor-analyze-usage.md: adds a who-can-view breakdown by role category (organization owners and billing admins for the entire org; cloud resource access roles for hosted deployments and serverless projects; connected cluster access roles for connected clusters); scopes the prepaid-credits item and invoice-check callout to Organization owner/Billing admin users; clarifies that cost history is available for resources currently in scope; and adds a note that organization-wide financial data stays owner/admin-only.deploy-manage/cloud-organization/billing/manage-billing-notifications.md: clarifies who can create, view, and manage a budget depending on its scope (organization vs. cloud resource).Internal tracking issue: elastic/platform-billing#7643
Generative AI disclosure
Tool(s) and model(s) used: Claude Code (Claude Opus 4.8)