Skip to content
CLD-020 Cloud Services

Cloud ServicesCLD-020

What is the difference between an administrator, account owner and ordinary user?

An account owner, administrator and ordinary user may all access the same cloud environment, but they do not necessarily have the same authority.

The account owner usually has the main contractual, billing or top-level control over the service. An administrator manages users, settings, permissions or security. An ordinary user normally accesses only the data and functions allowed by their role.

What this means in practice

A small personal service may combine owner and administrator powers in one account. A large organisation may divide administration across several specialist roles. An ordinary user may also be given temporary elevated permissions.

Some services also include guests, service accounts, application identities and delegated administrators. These can create activity outside the simple owner-administrator-user model.

For an investigation, identify the exact role at the relevant time. Permissions may change. A person who is an ordinary user today may have been an administrator when the event occurred.

Use precise language in statements and requests. Record whether the person was the contractual owner, tenant administrator, security administrator, file owner, ordinary user or guest.

What this may show

The account owner may be able to close the service, change billing or appoint administrators without routinely accessing user content. An administrator may reset credentials, create accounts, change policies or view audit logs. An ordinary user may create, edit, share or delete data within the permissions granted.

What this does not show on its own

The dangerous assumption is that these labels are fixed or mean the same thing across every provider.

What to do next

Obtain role-assignment history, administrator logs and policy records where available. Compare the recorded action with the permissions that account actually held.

Do not assume that account ownership proves operational control, or that an ordinary user lacked the ability to perform a significant action. Configuration and delegated access may alter the position.

Key takeaway

Separate contractual ownership, administrative authority and ordinary use, and establish the account’s actual permissions at the time of the event.

Keep moving

Where this question leads

These links explain why the next page may matter, rather than presenting an undifferentiated list.