Michael
My feedback
9 results found
-
17 votesMichael supported this idea ·
-
7 votesMichael supported this idea ·
-
466 votes
An error occurred while saving the comment An error occurred while saving the comment Michael commentedHi Andrew,
Thank you very much for your answer. Cross-Org Billing really helps us.
Do you think, it would be possible to set more than one "Billing Email Address" in billing profile? I asked the support, but it seems that you only can set up one address. This shouldn't be a big change. The billing mail should be sent to me and my colleague.I have seen that you cannot change the billing profile for the linked organization. If you would made this possible, it would be much easier to manage the accounts for our subsidiaries. Because then you would receive a separate invoice to a separate mail address.
Regards,
MichaelMichael supported this idea ·An error occurred while saving the comment Michael commented1. Each Organisation-Member is able to read the billing details of the organisation. This should be restricted. We facing problems with our governance, because each member is able to get details about billing in MongoDB Atlas.
2. As an Project-Owner, you are able to invite new member to you project and so implicitly to the organisation. But you are not able to delete member from the organisation. If you delete a member, he has still access to the organisation and is able to read the invoice. Even if that member has not access to any project.
3. Each member gets the invoice via mail. Again this is not a good idea from governance perspective. You can only restict this, by adding (only one) "Billing Email Address". There should be a solution, to send the invoice only to project owners or something like this. -
12 votesMichael supported this idea ·
-
25 votesMichael supported this idea ·
-
154 votesMichael supported this idea ·
-
42 votesMichael shared this idea ·
-
5 votesMichael supported this idea ·
-
86 votesMichael supported this idea ·
We also have a need for more granular permissions. To centrally monitor all configurations of our clusters, we want to use the API. We use the api to check whether audit is enabled and how audit is configured.
To check this, the api key must have project_owner or organization_owner permissions. This is very worrying from a security point of view, because it gives very powerful permissions. In this case it would be helpful to create a role with extended read permissions (>Organization Read Only).
I think that in the long run there is no way around the fact that users must be able to create their own roles.