[Yandex Cloud documentation](../../index.md) > [Yandex Cloud Billing](../index.md) > Access management

# Access management in Yandex Cloud Billing

## Billing account access {#billing-account}

[Access](../concepts/billing-account.md) to the billing account can be provided via the [Yandex Cloud Billing interface](https://center.yandex.cloud/billing/accounts) or the [Yandex Cloud API](../api-ref/authentication.md). A billing account can be created by users with a registered Yandex or Yandex 360 account:

* If you or your employee have no account yet, create one on [Yandex](https://passport.yandex.ru/registration) or [Yandex 360](https://yandex.com/support/business/add-users.html).
* If using a social network profile to log in to Yandex, [create a username and password](https://passport.yandex.ru/passport?mode=postregistration&create_login=1).

The operations a user can perform on a billing account depend on the assigned role. You can assign roles to a Yandex account, [service account](../../iam/concepts/users/service-accounts.md), [federated](../../iam/concepts/users/accounts.md#saml-federation) or [local](../../iam/concepts/users/accounts.md#local) users, [user group](../../organization/operations/manage-groups.md), [system group](../../iam/concepts/access-control/system-group.md), or [public group](../../iam/concepts/access-control/public-group.md).

{% note info %}

Access can only be granted to a user whose billing account has a cloud linked in [Identity and Access Management](../../iam/index.md).

{% endnote %}

## Roles this service has {#roles-list}

```mermaid
flowchart BT
    billing.accounts.viewer --> billing.accounts.accountant
    billing.accounts.viewer --> billing.accounts.editor
    billing.accounts.editor --> billing.accounts.admin
    billing.accounts.partnerAdmin --> billing.accounts.admin
    billing.partners.editor --> billing.accounts.admin
    billing.partners.editor --> billing.accounts.varWithoutDiscounts
    billing.accounts.admin --> billing.accounts.owner
    billing.accounts.varWithoutDiscounts --> billing.accounts.owner
    billing.accounts.member --> billing.accounts.viewer
```

### Service roles {#service-roles}

#### billing.accounts.member {#billing-accounts-member}

The `billing.accounts.member` role is granted automatically when a user is added to the service. It is required to display the selected [billing account](../concepts/billing-account.md) in the list of all user accounts.

#### billing.accounts.viewer {#billing-accounts-viewer}

To use the `billing.accounts.viewer` role, you need to assign it for a billing account. This role enables you to view billing account data, get information about resource consumption, monitor expenses, and export reconciliation reports and reporting documents.

{% cut "In Yandex Cloud Billing, users with this role can:" %}

* Display [billing accounts](../concepts/billing-account.md) in the list of all accounts.
* View billing account data.
* View and download [reporting (or closing) documents](../payment/documents.md).
* View and download generated reconciliation reports.
* Get and view notifications on consumption.
* Monitor expenses.
* [View usage details](../operations/check-charges.md).

{% endcut %}

#### billing.accounts.accountant {#billing-accounts-accountant}

To use the `billing.accounts.accountant` role, you need to assign it for a billing account. This role enables you to view billing account data, get information about resource consumption, monitor expenses, export reconciliation reports and reporting documents, create new reconciliation reports, and top up your personal account using a bank account.

{% cut "In Yandex Cloud Billing, users with this role can:" %}

* Display billing accounts in the list of all accounts.
* View billing account data.
* View and download [reporting (or closing) documents](../payment/documents.md).
* Generate new [reconciliation reports](../concepts/act.md#reconciliation-report).
* View and download generated reconciliation reports.
* Get and view notifications on consumption.
* Monitor expenses.
* [View usage details](../operations/check-charges.md).
* Top up their [personal account](../concepts/personal-account.md) using a bank account.

{% endcut %}


This role includes the `billing.accounts.viewer` permissions.

#### billing.partners.editor {#billing-partners-editor}

The `billing.partners.editor` role is assigned for a [billing account](../concepts/billing-account.md). It grants permission to edit information about a [partner](../../partner/program/var.md) and their products in the [partner product catalog](../../partner/program/var-tools.md#catalog).

#### billing.accounts.editor {#billing-accounts-editor}

To use the `billing.accounts.editor` role, you need to assign it for a billing account. It enables you to get payment invoices, redeem promo codes, link clouds and services to your billing account, create details export and budgets, generate reconciliation reports, and reserve resources.

{% cut "In Yandex Cloud Billing, users with this role can:" %}

* Display [billing accounts](../concepts/billing-account.md) in the list of all accounts.
* View billing account data.
* View [client offers](../concepts/glossary.md#client-offer).
* View and download [reporting (or closing) documents](../payment/documents.md).
* Generate new [reconciliation reports](../concepts/act.md#reconciliation-report).
* View and download generated reconciliation reports.
* Get and view notifications on consumption.
* Monitor expenses.
* [View usage details](../operations/check-charges.md).
* [Export details](../operations/get-folder-report.md).
* Create [budgets](../concepts/budget.md).
* [Reserve resource usage](../concepts/cvos.md).
* Top up their [personal account](../concepts/personal-account.md) using a bank account.
* Link [clouds](../../resource-manager/concepts/resources-hierarchy.md#cloud) to a billing account.
* Rename billing accounts.
* Redeem promo codes.

{% endcut %}

{% cut "On the Yandex Cloud partner portal, users with this role can:" %}

* Link [clouds](../../resource-manager/concepts/resources-hierarchy.md#cloud) to [subaccounts](../../partner/terms.md#sub-account).

{% endcut %}

This role includes the `billing.accounts.viewer` permissions.

#### billing.accounts.varWithoutDiscounts {#billing-accounts-var-without-discounts}

To use the `billing.accounts.varWithoutDiscounts` role, you need to assign it for a billing account. This role grants partner accounts all administrator privileges, except the permission to get information about discounts.

{% cut "In Yandex Cloud Billing, users with this role can:" %}

* Display [billing accounts](../concepts/billing-account.md) in the list of all accounts.
* View billing account data.
* View info on the [access permissions](../../iam/concepts/access-control/index.md) granted for the relevant billing accounts.
* View and download [reporting (or closing) documents](../payment/documents.md).
* Generate new [reconciliation reports](../concepts/act.md#reconciliation-report).
* View and download generated reconciliation reports.
* Get and view notifications on consumption.
* Monitor expenses.
* [View usage details](../operations/check-charges.md).
* [Export details](../operations/get-folder-report.md).
* Create [budgets](../concepts/budget.md).
* [Reserve resource usage](../concepts/cvos.md).
* Top up their [personal account](../concepts/personal-account.md) using a bank account.
* Link [clouds](../../resource-manager/concepts/resources-hierarchy.md#cloud) to a billing account.
* Rename billing accounts.
* Redeem promo codes.

{% endcut %}

{% cut "On the Yandex Cloud partner portal, users with this role can:" %}

* [Create](../../partner/operations/pin-client.md#client-entry) customer records ([subaccounts](../../partner/terms.md#sub-account)).
* View the list of subaccounts and info on them.
* Activate subaccounts.
* Suspend subaccounts.
* Re-activate subaccounts.
* Link [clouds](../../resource-manager/concepts/resources-hierarchy.md#cloud) to subaccounts.
* [Manage](../../partner/operations/access/partners-account.md) access permissions to subaccounts.
* [View](../../partner/operations/get-client-stat.md) the details of how the customers use services.

{% endcut %}

This role includes the `billing.partners.editor` permissions.

#### billing.accounts.admin {#billing-accounts-admin}

To use the `billing.accounts.admin` role, you need to assign it for a billing account. It enables managing access to a billing account (except for `billing.accounts.owner`).

{% cut "In Yandex Cloud Billing, users with this role can:" %}

* Display [billing accounts](../concepts/billing-account.md) in the list of all accounts.
* View billing account data.
* View [client offers](../concepts/glossary.md#client-offer).
* View info on the [access permissions](../../iam/concepts/access-control/index.md) granted for the relevant billing accounts and modify such permissions (except for assigning and revoking the `billing.accounts.owner` role).
* Activate, deactivate, or modify the [technical support](../../support/overview.md) service plan, as well as change the billing account from which the payment is debited.
* View and download [reporting (or closing) documents](../payment/documents.md).
* Generate new [reconciliation reports](../concepts/act.md#reconciliation-report).
* View and download generated reconciliation reports.
* Get and view notifications on consumption.
* Monitor expenses.
* [View usage details](../operations/check-charges.md).
* [Export details](../operations/get-folder-report.md).
* Create [budgets](../concepts/budget.md).
* [Reserve resource usage](../concepts/cvos.md).
* Top up their [personal account](../concepts/personal-account.md) using a bank account.
* Link [clouds](../../resource-manager/concepts/resources-hierarchy.md#cloud) to a billing account.
* Rename billing accounts.
* Redeem promo codes.

{% endcut %}

{% cut "On the Yandex Cloud partner portal, users with this role can:" %}

* [Create](../../partner/operations/pin-client.md#client-entry) customer records ([subaccounts](../../partner/terms.md#sub-account)).
* View the list of subaccounts and info on them, including personal data.
* Activate subaccounts.
* Suspend subaccounts.
* Re-activate subaccounts.
* Link [clouds](../../resource-manager/concepts/resources-hierarchy.md#cloud) to subaccounts.
* [Manage](../../partner/operations/access/partners-account.md) access permissions to subaccounts.
* [View](../../partner/operations/get-client-stat.md) the details of how the customers use services.
* View the list of [partner discounts](../../partner/portal.md#premium) and info on them.

{% endcut %}

This role includes the `billing.accounts.editor`, `billing.accounts.partnerAdmin`, and `billing.partners.editor` permissions.

#### billing.accounts.owner {#billing-accounts-owner}

When creating your billing account, you get the `billing.accounts.owner` role automatically. Any user with the `billing.accounts.owner` role can revoke this role from the billing account creator and change the owner.

{% cut "In Yandex Cloud Billing, users with this role can:" %}

* Display [billing accounts](../concepts/billing-account.md) in the list of all accounts.
* View billing account data.
* View [client offers](../concepts/glossary.md#client-offer).
* View info on the [access permissions](../../iam/concepts/access-control/index.md) granted for the relevant billing accounts and modify such permissions.
* Activate, deactivate, or modify the [technical support](../../support/overview.md) service plan, as well as change the billing account from which the payment is debited.
* View and download [reporting (or closing) documents](../payment/documents.md).
* Generate new [reconciliation reports](../concepts/act.md#reconciliation-report).
* View and download generated reconciliation reports.
* Get and view notifications on consumption.
* Monitor expenses.
* [View usage details](../operations/check-charges.md).
* [Export details](../operations/get-folder-report.md).
* Create [budgets](../concepts/budget.md).
* [Reserve resource usage](../concepts/cvos.md).
* Top up their [personal account](../concepts/personal-account.md) using a bank account.
* Top up their personal account using a credit or debit card.
* Link [clouds](../../resource-manager/concepts/resources-hierarchy.md#cloud) to a billing account.
* Rename billing accounts.
* Changing payer contact details.
* Change payment details.
* Change their credit or debit card details.
* Change the payment method.
* Redeem promo codes.
* Activate the [trial period](../concepts/trial-period.md).
* Activate the [paid version](../../getting-started/free-trial/concepts/upgrade-to-paid.md).
* [Delete](../operations/delete-account.md) billing accounts.

{% endcut %}

{% cut "On the Yandex Cloud partner portal, users with this role can:" %}

* [Create](../../partner/operations/pin-client.md#client-entry) customer records ([subaccounts](../../partner/terms.md#sub-account)).
* View the list of subaccounts and info on them, including personal data.
* Update subaccount records.
* Activate subaccounts.
* Suspend subaccounts.
* Re-activate subaccounts.
* Delete subaccounts without customer confirmation.
* Link [clouds](../../resource-manager/concepts/resources-hierarchy.md#cloud) to subaccounts.
* [Manage](../../partner/operations/access/partners-account.md) access permissions to subaccounts.
* [View](../../partner/operations/get-client-stat.md) the details of how the customers use services.
* View the list of [partner discounts](../../partner/portal.md#premium) and info on them.

{% endcut %}

This role includes the `billing.accounts.admin` and `billing.accounts.varWithoutDiscounts` permissions.

### Primitive roles {#primitive-roles}

Primitive roles are aggregator roles that define user permissions to access services. In Yandex Cloud Billing, these roles match the following `billing.accounts.*` roles:

* `auditor`: Same as `billing.accounts.viewer` (with some limitations).
* `viewer`: Same as `billing.accounts.viewer`.
* `editor`: Same as `billing.accounts.editor`.
* `admin`: Same as `billing.accounts.admin`.

Primitive roles can only be assigned to users in the **Users** list.

### Available operations {#available-operations}

The table below provides a list of operations available to each role type.

| Operations                                                | `owner`                                | `viewer`                               | `accountant`                           | `editor`                               | `admin`                                |
|---------------------------------------------------------|----------------------------------------|----------------------------------------|----------------------------------------|----------------------------------------|----------------------------------------|
| Displaying a billing account in the list of all user accounts       | ![image](../../_assets/common/yes.svg) | ![image](../../_assets/common/yes.svg) | ![image](../../_assets/common/yes.svg) | ![image](../../_assets/common/yes.svg) | ![image](../../_assets/common/yes.svg) |
| Viewing billing account information                     | ![image](../../_assets/common/yes.svg) | ![image](../../_assets/common/yes.svg) | ![image](../../_assets/common/yes.svg) | ![image](../../_assets/common/yes.svg) | ![image](../../_assets/common/yes.svg) |
| Viewing and receiving usage notifications          | ![image](../../_assets/common/yes.svg) | ![image](../../_assets/common/yes.svg) | ![image](../../_assets/common/yes.svg) | ![image](../../_assets/common/yes.svg) | ![image](../../_assets/common/yes.svg) |
| Viewing and downloading reporting (closing) documents | ![image](../../_assets/common/yes.svg) | ![image](../../_assets/common/yes.svg) | ![image](../../_assets/common/yes.svg) | ![image](../../_assets/common/yes.svg) | ![image](../../_assets/common/yes.svg) |
| Viewing and downloading generated reconciliation reports  | ![image](../../_assets/common/yes.svg) | ![image](../../_assets/common/yes.svg) | ![image](../../_assets/common/yes.svg) | ![image](../../_assets/common/yes.svg) | ![image](../../_assets/common/yes.svg) |
| Checking expenses                                       | ![image](../../_assets/common/yes.svg) | ![image](../../_assets/common/yes.svg) | ![image](../../_assets/common/yes.svg) | ![image](../../_assets/common/yes.svg) | ![image](../../_assets/common/yes.svg) |
| Accessing usage details                                    | ![image](../../_assets/common/yes.svg) | ![image](../../_assets/common/yes.svg) | ![image](../../_assets/common/yes.svg) | ![image](../../_assets/common/yes.svg) | ![image](../../_assets/common/yes.svg) |
| Topping up your personal account using a bank account    | ![image](../../_assets/common/yes.svg) | ![image](../../_assets/common/no.svg)  | ![image](../../_assets/common/yes.svg) | ![image](../../_assets/common/yes.svg) | ![image](../../_assets/common/yes.svg) |
| Generating a new reconciliation report                            | ![image](../../_assets/common/yes.svg) | ![image](../../_assets/common/no.svg)  | ![image](../../_assets/common/yes.svg) | ![image](../../_assets/common/yes.svg) | ![image](../../_assets/common/yes.svg) |
| Activating promo codes                                    | ![image](../../_assets/common/yes.svg) | ![image](../../_assets/common/no.svg)  | ![image](../../_assets/common/no.svg)  | ![image](../../_assets/common/yes.svg) | ![image](../../_assets/common/yes.svg) |
| Linking a cloud organization and other entities to a billing account | ![image](../../_assets/common/yes.svg) | ![image](../../_assets/common/no.svg)  | ![image](../../_assets/common/no.svg)  | ![image](../../_assets/common/yes.svg) | ![image](../../_assets/common/yes.svg) |
| Link with a cloud organization                           | ![image](../../_assets/common/yes.svg) | ![image](../../_assets/common/no.svg)  | ![image](../../_assets/common/no.svg)  | ![image](../../_assets/common/no.svg)  | ![image](../../_assets/common/no.svg)  |
| Creating details export                           | ![image](../../_assets/common/yes.svg) | ![image](../../_assets/common/no.svg)  | ![image](../../_assets/common/no.svg)  | ![image](../../_assets/common/yes.svg) | ![image](../../_assets/common/yes.svg) |
| Creating budget                                        | ![image](../../_assets/common/yes.svg) | ![image](../../_assets/common/no.svg)  | ![image](../../_assets/common/no.svg)  | ![image](../../_assets/common/yes.svg) | ![image](../../_assets/common/yes.svg) |
| Resource allocation                                 | ![image](../../_assets/common/yes.svg) | ![image](../../_assets/common/no.svg)  | ![image](../../_assets/common/no.svg)  | ![image](../../_assets/common/yes.svg) | ![image](../../_assets/common/yes.svg) |
| Renaming a billing account                      | ![image](../../_assets/common/yes.svg) | ![image](../../_assets/common/no.svg)  | ![image](../../_assets/common/no.svg)  | ![image](../../_assets/common/yes.svg) | ![image](../../_assets/common/yes.svg) |
| Viewing commercial offers                  | ![image](../../_assets/common/yes.svg) | ![image](../../_assets/common/no.svg)  | ![image](../../_assets/common/no.svg)  | ![image](../../_assets/common/yes.svg) | ![image](../../_assets/common/yes.svg) |
| Assigning roles to billing accounts                       | ![image](../../_assets/common/yes.svg) | ![image](../../_assets/common/no.svg)  | ![image](../../_assets/common/no.svg)  | ![image](../../_assets/common/no.svg)  | ![image](../../_assets/common/yes.svg) | 
| Viewing and editing roles                         | ![image](../../_assets/common/yes.svg) | ![image](../../_assets/common/no.svg)  | ![image](../../_assets/common/no.svg)  | ![image](../../_assets/common/no.svg)  | ![image](../../_assets/common/yes.svg) | 
| Managing technical support plan                | ![image](../../_assets/common/yes.svg) | ![image](../../_assets/common/no.svg)  | ![image](../../_assets/common/no.svg)  | ![image](../../_assets/common/no.svg)  | ![image](../../_assets/common/yes.svg) | 
| Changing payer contact details                         | ![image](../../_assets/common/yes.svg) | ![image](../../_assets/common/no.svg)  | ![image](../../_assets/common/no.svg)  | ![image](../../_assets/common/no.svg)  | ![image](../../_assets/common/no.svg)  |
| Changing billing details                          | ![image](../../_assets/common/yes.svg) | ![image](../../_assets/common/no.svg)  | ![image](../../_assets/common/no.svg)  | ![image](../../_assets/common/no.svg)  | ![image](../../_assets/common/no.svg)  |
| Changing bank cards                              | ![image](../../_assets/common/yes.svg) | ![image](../../_assets/common/no.svg)  | ![image](../../_assets/common/no.svg)  | ![image](../../_assets/common/no.svg)  | ![image](../../_assets/common/no.svg)  |
| Changing payment methods                                | ![image](../../_assets/common/yes.svg) | ![image](../../_assets/common/no.svg)  | ![image](../../_assets/common/no.svg)  | ![image](../../_assets/common/no.svg)  | ![image](../../_assets/common/no.svg)  |
| Activating paid version                                | ![image](../../_assets/common/yes.svg) | ![image](../../_assets/common/no.svg)  | ![image](../../_assets/common/no.svg)  | ![image](../../_assets/common/no.svg)  | ![image](../../_assets/common/no.svg)  |
| Topping up your personal account using a credit or debit card    | ![image](../../_assets/common/yes.svg) | ![image](../../_assets/common/no.svg)  | ![image](../../_assets/common/no.svg)  | ![image](../../_assets/common/no.svg)  | ![image](../../_assets/common/no.svg)  |
| Accepting commercial offers                      | ![image](../../_assets/common/yes.svg) | ![image](../../_assets/common/no.svg)  | ![image](../../_assets/common/no.svg)  | ![image](../../_assets/common/no.svg)  | ![image](../../_assets/common/no.svg)  |

## Adding a user {#set-member-role}

The steps for adding a new billing account user depend on whether the billing account is associated with an organization.

{% list tabs group=instructions %}

- Accounts associated with an organization {#organization}

  [Assign](#set-role) the required role for the billing account to a user or service account in your organization.

- Accoounts associated with no organization {#no-organization}

  {% note info %}

  To add a new billing account user, you need the `billing.accounts.owner` or `billing.accounts.admin` role.

  {% endnote %}

  1. Go to [**Yandex Cloud Billing**](https://center.yandex.cloud/billing/accounts).
  1. Select a billing account.
  1. Go to the **Access management** page.
  1. At the top right, click **Add user**.
  1. Select the user from the drop-down list. The list shows users whose clouds are linked to your billing account.
  1. Click **Add**.

  The user or service account will get the `billing.accounts.member` role and included in the **Users** list. To grant billing account access, assign them the required role.

{% endlist %}

## Assigning roles {#set-role}

The steps for assigning a role for a billing account depend on whether the billing account is linked to the organization.

{% list tabs group=instructions %}

- Accounts associated with an organization {#organization}

  A user with the `billing.accounts.admin` role can grant access to the billing account to any user or service account within the same organization. Proceed as follows:

  1. [Make sure](../../organization/operations/users-get.md) that the user you need belongs to your organization. If not, [add them](../../organization/operations/add-account.md).
  1. Go to [**Yandex Cloud Billing**](https://center.yandex.cloud/billing/accounts).
  1. Select a billing account.
  1. In the left-hand panel, select ![persons](../../_assets/console-icons/persons.svg) **Access management**.
  1. At the top right, click **Assign roles**. In the window that opens:

     1. Select a user, service account, or user group. If required, use the search bar.
     1. Click ![image](../../_assets/create.svg) **Add role** and select the role.
     1. Click **Save**.

  {% note info %}

  If you assign the Yandex Cloud Billing service role to an organization, all billing accounts within this organization will also assume this role.

  {% endnote %}

- Accoounts associated with no organization {#no-organization}

  A user with the `billing.accounts.admin` role can grant access to the billing account to any user or service account on the **Users** list. Proceed as follows:
 
  1. Go to [**Yandex Cloud Billing**](https://center.yandex.cloud/billing/accounts).
  1. Select a billing account.
  1. In the left-hand panel, select ![persons](../../_assets/console-icons/persons.svg) **Access management**.
  1. Find the required user, service account, or user group in the users list or use the filter. 
  1. In the line with the required user, service account, or group, click ![image](../../_assets/console-icons/ellipsis.svg) and select ![pencil](../../_assets/console-icons/pencil.svg) **Edit roles**. In the window that opens:
  
      1. Click ![image](../../_assets/create.svg) **Add role**.
      1. Select a role from the list.
      1. Click **Save**.

{% endlist %}

The role will be assigned without expiration.

## Revoking roles {#delete-role}

The steps for revoking a role for a billing account depend on whether the billing account is linked to the organization.

{% list tabs group=instructions %}

- Accounts associated with an organization {#organization}

  A user with the `billing.accounts.admin` role can revoke a billing account role from a user or service account in their organization at any time. Proceed as follows:

  1. Go to [**Yandex Cloud Billing**](https://center.yandex.cloud/billing/accounts).
  1. Select a billing account.
  1. In the left-hand panel, select ![persons](../../_assets/console-icons/persons.svg) **Access management**.
  1. Find the required user, service account, or user group in the users list or use the filter.
  1. In the line with the required user, service account, or group, click ![image](../../_assets/horizontal-ellipsis.svg) and select ![pencil](../../_assets/console-icons/pencil.svg) **Edit roles**. In the window that opens:

      1. Click ![image](../../_assets/cross.svg) to the right of the role you want to revoke.
      1. Click **Save**. The role will be revoked.

- Accoounts associated with no organization {#no-organization}

  A user with the `billing.accounts.admin` role can revoke a billing account role from a user or service account on the list at any time. Proceed as follows:

  1. Go to [**Yandex Cloud Billing**](https://center.yandex.cloud/billing/accounts).
  1. Select a billing account.
  1. In the left-hand panel, select ![persons](../../_assets/console-icons/persons.svg) **Access management**.
  1. Find the required user, service account, or user group in the users list or use the filter. 
  1. In the line with the required user, service account, or group, click ![image](../../_assets/horizontal-ellipsis.svg) and select ![pencil](../../_assets/console-icons/pencil.svg) **Edit roles**. In the window that opens:

      1. Click ![image](../../_assets/cross.svg) to the right of the role you want to revoke.
      1. Click **Save**. The role will be revoked.

  {% note info %}

  If the `billing.accounts.member` role is revoked, the user will not be able to access the billing account.

  {% endnote %}

{% endlist %}

## Deleting a billing account user {#delete-user}

You can only delete users from billing accounts not linked to the organization. Proceed as follows:

1. Go to [**Yandex Cloud Billing**](https://center.yandex.cloud/billing/accounts).
1. Select a billing account.
1. In the left-hand panel, select ![persons](../../_assets/console-icons/persons.svg) **Access management** and find the user or service account in the list that opens.

    Optionally, use the filter in the right part of the screen.
1. In the line with the user or service account, click ![image](../../_assets/console-icons/ellipsis.svg) and select **Remove user**.
1. This will delete the user from the list of the billing account users.

If the billing account is linked to the organization, simply [revoke](#delete-role) the role from the user or service account. You can also [delete a user from the organization](../../organization/operations/edit-account.md) to revoke access to all its clouds and resources.

You can also [deactivate](../../organization/operations/user-pools/deactivate-user.md) a [federated](../../iam/concepts/users/accounts.md#saml-federation) or [local](../../iam/concepts/users/accounts.md#local) user. As a result, the user will lose access to the organization's resources until [reactivated](../../organization/operations/user-pools/activate-user.md).