Official agent skill

Admin

by grafana in grafana/skills

Manage Grafana Cloud accounts — organizations, stacks, RBAC roles and assignments, SSO/SAML/OAuth/GitHub auth, service accounts for CI/CD, user invites, team membership, and API-driven provisioning.

OfficialApache-2.0Auto-check passedDevOps & Cloud

Install Admin

skills CLI
$ npx skills add grafana/skills --skill admin -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install grafana/skills admin --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/grafana/skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/grafana-cloud/admin .claude/skills/admin && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
admin
GitHub stars
278
Token cost
~1.5k tokens
SKILL.md length
262 words
Files
4 (incl. references)
Skills in repo
51
Repo updated
First seen
Licence
Apache-2.0

At a glance

Manage Grafana Cloud accounts — organizations, stacks, RBAC roles and assignments, SSO/SAML/OAuth/GitHub auth, service accounts for CI/CD, user invites, team membership, and API-driven provisioning.

  • Works in 5 steps: Invite users via POST /api/org/invites… → Create the team via POST /api/teams → Add each user via POST… → …
  • Managing Grafana Cloud access
  • SKILL.md covers Common Workflows, Organization and Stack Structure, User Roles and RBAC, plus 2 more sections
  • Calls curl and jq; reaches grafana.com

What it does

Admin is an agent skill from grafana/skills, published by the product's own GitHub organization. Manage Grafana Cloud accounts — organizations, stacks, RBAC roles and assignments, SSO/SAML/OAuth/GitHub auth, service accounts for CI/CD, user invites, team membership, and API-driven provisioning. Creates stacks via the Cloud API, mints service-account tokens, applies role assignments, configures SSO providers, and provisions teams/folders/dashboards via Terraform. Use when managing Grafana Cloud access, configuring SSO/SAML/OAuth, setting up service accounts for Terraform/CI/CD, assigning RBAC roles, inviting…

Its SKILL.md is about 1.5k tokens, which your agent loads only when the skill is triggered. The skill folder holds 4 other files, including reference files (for example `references/api-reference.md`, `references/sso.md` and `references/terraform.md`).

It sits in DevOps & Cloud, covering Monitoring and alerting, Authentication and Authorization and RBAC. It works with Grafana, Terraform and GitHub. The licence is Apache-2.0.

When your agent uses it

  • Managing Grafana Cloud access
  • Configuring SSO/SAML/OAuth
  • Setting up service accounts for Terraform/CI/CD
  • Assigning RBAC roles

Example prompts

  • “set up SSO”
  • “create a stack”
  • “make a service account”
  • “/admin”

Workflow steps

5 steps, taken from the first numbered list in SKILL.md.

  1. Invite users via POST /api/org/invites (one curl per user — see references/api-reference.md § Stack API)
  2. Create the team via POST /api/teams
  3. Add each user via POST /api/teams/{teamId}/members
  4. Assign an RBAC role to the team (see § RBAC below)
  5. Verify: GET /api/teams/{teamId}/members returns the expected user list

What it can do on your machine

Read from SKILL.md and the folder at commit 1ccacf2. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • curl
    • jq

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    Hosts in commands or code, which the agent is likely to contact:

    • grafana.com

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Admin loads about 1.5k tokens when it runs, and up to ~3.4k if it reads all its reference files. Until then it costs about 197 tokens; SKILL.md has 262 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~197
When it runs · the whole SKILL.md, loaded when a task matches
~1.5k
With references · SKILL.md plus every file in references/, read only if the agent opens them
~3.4k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from grafana/skills at commit 1ccacf2, republished under its Apache-2.0 licence (© grafana). 262 words, ~1,492 tokens.

Download SKILL.mdSave it as .claude/skills/admin/SKILL.md (or your agent's skills folder). This skill also uses 3 other files; get the full folder from GitHub.
name
admin
description
Manage Grafana Cloud accounts — organizations, stacks, RBAC roles and assignments, SSO/SAML/OAuth/GitHub auth, service accounts for CI/CD, user invites, team membership, and API-driven provisioning. Creates stacks via the Cloud API, mints service-account tokens, applies role assignments, configures SSO providers, and provisions teams/folders/dashboards via Terraform. Use when managing Grafana Cloud access, configuring SSO/SAML/OAuth, setting up service accounts for Terraform/CI/CD, assigning RBAC roles, inviting users, managing multiple stacks or organizations, provisioning cloud resources via API or Terraform, or auditing admin actions — even when the user says "set up SSO", "create a stack", "make a service account", or "onboard a team" without explicitly saying "admin".
license
Apache-2.0

Grafana Cloud Admin

Docs: https://grafana.com/docs/grafana-cloud/account-management.md

Common Workflows

Setting up a new stack
bash
# 1. Create the stack via Cloud API
curl -X POST https://grafana.com/api/instances \
  -H "Authorization: Bearer <grafana-com-api-key>" \
  -H "Content-Type: application/json" \
  -d '{"name": "my-new-stack", "slug": "my-new-stack", "region": "us-east-0", "plan": "grafana-cloud-free"}'

# 2. Verify the stack is reachable (poll until 200)
until curl -fs https://my-new-stack.grafana.net/api/health > /dev/null; do sleep 2; done

# 3. Mint an admin service-account token (see § Service Accounts below)

# 4. Test the token
curl https://my-new-stack.grafana.net/api/org -H "Authorization: Bearer <token>"
# Returns 200 + org JSON → token works
Onboarding a team
  1. Invite users via POST /api/org/invites (one curl per user — see references/api-reference.md § Stack API)
  2. Create the team via POST /api/teams
  3. Add each user via POST /api/teams/{teamId}/members
  4. Assign an RBAC role to the team (see § RBAC below)
  5. Verify: GET /api/teams/{teamId}/members returns the expected user list
Configuring SSO (Okta / SAML / GitHub)
  1. Pick the provider config from references/sso.md and drop into grafana.ini
  2. Restart Grafana
  3. Always validate in an incognito window before announcing: see references/sso.md § Verifying SSO for the 5-step verification + role-mapping debug pattern
Deleting a stack (destructive)
bash
# 1. Delete via Cloud API
curl -X DELETE https://grafana.com/api/instances/{id} \
  -H "Authorization: Bearer <grafana-com-api-key>"

# 2. Verify the stack is gone (must return 404)
curl https://grafana.com/api/instances/{id} \
  -H "Authorization: Bearer <grafana-com-api-key>"

If the GET still returns 200 after a few seconds, the delete didn't apply — re-check the stack ID and Cloud API key.

Organization and Stack Structure

Grafana Cloud Account
└── Organization (billing unit)
    ├── Stack 1 (prod)   → dedicated Grafana, Prometheus, Loki, Tempo URLs
    ├── Stack 2 (staging)
    └── Stack 3 (dev)
  • Organization: top-level account with billing, users, API keys, stacks
  • Stack: dedicated Grafana + LGTM instance with its own URLs and credentials

User Roles

RoleScopePermissions
Org AdminOrganizationManage stacks, users, billing, API keys
AdminStackData sources, plugins, users, provisioning
EditorStackCreate/edit dashboards, alerts
ViewerStackRead-only dashboards

RBAC

Define a custom role + assignment in provisioning YAML:

yaml
# provisioning/access-control/roles.yaml
apiVersion: 1
roles:
  - name: TeamDashboardEditor
    description: Edit dashboards within team folder
    permissions:
      - action: dashboards:read
        scope: folders:UID:team-folder
      - action: dashboards:write
        scope: folders:UID:team-folder
      - action: dashboards:create
        scope: folders:UID:team-folder
yaml
# provisioning/access-control/assignments.yaml
apiVersion: 1
roleAssignments:
  - roleName: TeamDashboardEditor
    users:
      - alice@example.com
      - bob@example.com
    teams:
      - platform-team

After committing the YAML and restarting Grafana, verify the role applied: GET /api/access-control/roles | jq '.[] | select(.name=="TeamDashboardEditor")'.

Service Accounts

Service accounts are the recommended way for programmatic access (CI/CD, Terraform, agents).

bash
# 1. Create the service account
curl -X POST https://yourstack.grafana.net/api/serviceaccounts \
  -H "Authorization: Bearer <admin-token>" \
  -H "Content-Type: application/json" \
  -d '{"name": "terraform-provisioner", "role": "Admin", "isDisabled": false}'

# 2. Mint a token for it
curl -X POST https://yourstack.grafana.net/api/serviceaccounts/{id}/tokens \
  -H "Authorization: Bearer <admin-token>" \
  -H "Content-Type: application/json" \
  -d '{"name": "ci-token", "secondsToLive": 0}'

# 3. Verify the token works (test on a harmless endpoint)
curl https://yourstack.grafana.net/api/org \
  -H "Authorization: Bearer <new-token>"
# 200 + org JSON → token works. Anything else → re-check role assignment in step 1.

Provisioning equivalent (YAML, declarative):

yaml
# provisioning/access-control/service_accounts.yaml
apiVersion: 1
serviceAccounts:
  - name: alloy-writer
    orgId: 1
    role: Editor
    tokens:
      - name: alloy-token

References

  • references/sso.md — OAuth / SAML / GitHub OAuth config + the 5-step SSO verification pattern + common failure modes
  • references/terraform.md — Terraform provider config + common resource patterns (teams, users, folders, dashboards) + drift troubleshooting
  • references/api-reference.md — full Cloud API + Stack API endpoint reference + audit-log queries

© grafana, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 3 other files (references) in skills/grafana-cloud/admin of grafana/skills.

  • SKILL.md
  • references/api-reference.md
  • references/sso.md
  • references/terraform.md

Open the folder on GitHubat commit 1ccacf2

Compare with similar skills

Admin next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Admin compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Admin this skillgrafana/skills278—~1.5kAutomated safety check: PassApache-2.0
AWS GitHub Oidc Scoped Rolemizchi/skills356—~1.6kAutomated safety check: PassNone
Neo4j Aura Provisioning Skillneo4j-contrib/neo4j-skills114—~3.7kAutomated safety check: NotesMIT
Cloud Devopsdavila7/claude-code-templates32k4 repos~1.4kAutomated safety check: PassMIT
Devops Pipelineluongnv89/skills131—~4.8kAutomated safety check: PassMIT
Sdaf Plan And Test SemanticsAzure/sap-automation145—~1.6kAutomated safety check: PassMIT

Similar skills

  • OpenTofu/Terraform pattern for GitHub Actions OIDC trust with AWS IAM.

    356 GitHub stars~1.6k tokensUpdated 5 days ago
    DevOps & CloudAuto-check passed
  • Neo4j Aura Provisioning Skill

    neo4j-contrib/neo4j-skills

    Provisions and manages Neo4j Aura instances via CLI (aura-cli v1.7+) or REST API.

    114 GitHub stars~3.7k tokensUpdated today
    DevOps & CloudAuto-check: notes
  • Cloud Devops

    davila7/claude-code-templates

    Cloud infrastructure and DevOps workflow covering AWS, Azure, GCP, Kubernetes, Terraform, CI/CD, monitoring, and cloud-native development.

    32k GitHub starsUsed in 4 repos~1.4k tokens
    DevOps & CloudAuto-check passed
  • Devops Pipeline

    luongnv89/skills

    Configure pre-commit hooks and lean GitHub Actions for shift-left quality assurance.

    131 GitHub stars~4.8k tokensUpdated today
    DevOps & CloudAuto-check passed
  • Sdaf Plan And Test Semantics

    Azure/sap-automation

    Official

    Explain SDAF plan-only / test / apply semantics without pretending they are universal.

    145 GitHub stars~1.6k tokensUpdated today
    DevOps & CloudAuto-check passed
  • Platform Engineering

    magnus919/agent-skills

    A skill your agent uses when building or operating internal developer platforms: infrastructure as code, CI/CD, container orchestration, service networking, secrets, and observability, or when…

    111 GitHub stars~2.4k tokensUpdated yesterday
    DevOps & CloudAuto-check passed

More from grafana/skills

All 51 skills in this repo
  • K6 Docs

    grafana/skills

    Official

    Write or review k6 documentation across the three k6 repositories - k6-DefinitelyTyped (TypeScript types), k6-docs (user documentation), and k6 (release notes / changelog).

    278 GitHub stars~678 tokensUpdated today
    Auto-check passed
  • Alerting Irm

    grafana/skills

    Official

    Configure Grafana Alerting, Incident Response Management (IRM), and SLOs end-to-end — provisions Grafana-managed and data-source-managed alert rules, contact points (Slack/PagerDuty/email/webhook)…

    278 GitHub starsUsed in 1 repo~1.9k tokens
    Auto-check passed
  • Dashboarding

    grafana/skills

    Official

    Build, modify, and ship Grafana dashboards as JSON via the HTTP API — panel types (timeseries / stat / gauge / table / heatmap / logs / traces / node-graph), gridPos 24-column layout, units…

    278 GitHub starsUsed in 1 repo~1.4k tokens
    Auto-check passed
  • K6 Perf Test Website

    grafana/skills

    Official

    A skill your agent uses when the user wants to performance-test, load-test, or stress-test a public website end-to-end with k6.

    278 GitHub stars~3.3k tokensUpdated today
    Auto-check passed
  • Promql

    grafana/skills

    Official

    Write, validate, and optimize PromQL for Prometheus / Grafana Mimir / Grafana Cloud Metrics.

    278 GitHub starsUsed in 1 repo~1.1k tokens
    Auto-check passed
  • Adaptive Metrics

    grafana/skills

    Official

    Cut Grafana Cloud Metrics cost by shrinking active-series count with Adaptive Metrics aggregation rules — auto-recommendations from query history, custom exact/regex rules, label-drop config…

    278 GitHub stars~1.3k tokensUpdated today
    Auto-check passed

Questions about Admin

What does Admin do?

Manage Grafana Cloud accounts — organizations, stacks, RBAC roles and assignments, SSO/SAML/OAuth/GitHub auth, service accounts for CI/CD, user invites, team membership, and API-driven provisioning. Admin is an agent skill from grafana/skills, published by the product's own GitHub organization. Manage Grafana Cloud accounts — organizations, stacks, RBAC roles and assignments, SSO/SAML/OAuth/GitHub auth, service accounts for CI/CD, user invites, team membership, and API-driven provisioning.

When should I use Admin?

Admin fits situations like: managing Grafana Cloud access; configuring SSO/SAML/OAuth; setting up service accounts for Terraform/CI/CD; assigning RBAC roles.

How do I install Admin in Claude Code?

Run `npx skills add grafana/skills --skill admin -a claude-code`. Or copy the skill folder (skills/grafana-cloud/admin in grafana/skills) into .claude/skills/admin in your project. Claude Code loads it when a task matches its description.

How do I install Admin in Codex?

Run `npx skills add grafana/skills --skill admin -a codex`. Or copy the skill folder (skills/grafana-cloud/admin in grafana/skills) into .agents/skills/admin in your project. Codex loads it when a task matches its description.

Can I use Admin in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add grafana/skills --skill admin -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/admin, .gemini/skills/admin, .github/skills/admin and .opencode/skills/admin in your project.

What does Admin need to run?

Going by SKILL.md and its folder, Admin needs the command-line tools its instructions call (curl and jq).

Does Admin access the network?

SKILL.md names 1 domain. In commands or code: grafana.com; the agent is likely to contact it when it follows the instructions. This is read from the text; nothing was executed.

Is Admin safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Admin use?

Admin is published under the Apache-2.0 licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Admin use?

About 1.5k tokens (SKILL.md is roughly 6k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 2k tokens, read only when the agent opens those files.

What are the alternatives to Admin?

Skills that share tags, products or a category with Admin: AWS GitHub Oidc Scoped Role (mizchi/skills, 356 stars), Neo4j Aura Provisioning Skill (neo4j-contrib/neo4j-skills, 114 stars), Cloud Devops (davila7/claude-code-templates, 32k stars) and Devops Pipeline (luongnv89/skills, 131 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Admin?

grafana (a GitHub organization, an official publisher) maintains it in grafana/skills, which has 278 GitHub stars. The repository holds 51 skills in this directory. The repository was last updated on October 6, 2026.

Source: grafana/skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.