# A user who can create, delete their indexes but restricted to deleting others'

**URL:** <https://discuss.elastic.co/t/a-user-who-can-create-delete-their-indexes-but-restricted-to-deleting-others/351296>\
**Category:** Elasticsearch\
**Created:** [January 17, 2024, 4:20pm UTC](https://discuss.elastic.co/t/a-user-who-can-create-delete-their-indexes-but-restricted-to-deleting-others/351296 "2024-01-17T16:20:04Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![jeannshuti](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jeannshuti/32/130870_2.png) [@jeannshuti](https://discuss.elastic.co/u/jeannshuti)\
**Post date:** [January 17, 2024, 4:20pm UTC](https://discuss.elastic.co/t/a-user-who-can-create-delete-their-indexes-but-restricted-to-deleting-others/351296/1 "2024-01-17T16:20:04Z")

</div>

I am new to the ELK stack and I am trying to find a built-in role that could allow a user to create and delete their own indexes but restricted to deleting others' indexes (read-only). Is there any specific role that has these privileges? I went through this [Built-in roles | Elasticsearch Guide [8.12] | Elastic](https://www.elastic.co/guide/en/elasticsearch/reference/current/built-in-roles.html) and couldn't find any.

Also, any suggestion would be highly appreciated.

---

<div class="post-metadata">

**Author:** ![jessgarson](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jessgarson/32/129841_2.png) [@jessgarson](https://discuss.elastic.co/u/jessgarson)\
**Post date:** [January 17, 2024, 6:03pm UTC](https://discuss.elastic.co/t/a-user-who-can-create-delete-their-indexes-but-restricted-to-deleting-others/351296/2 "2024-01-17T18:03:45Z")

</div>

Welcome @jeannshuti.

I don't know of a specific role that fits precisely. Have you considered [creating custom roles](https://www.elastic.co/guide/en/elasticsearch/reference/7.17/custom-roles-authorization.html)?

---

<div class="post-metadata">

**Author:** ![jeannshuti](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jeannshuti/32/130870_2.png) [@jeannshuti](https://discuss.elastic.co/u/jeannshuti)\
**Post date:** [January 22, 2024, 1:35pm UTC](https://discuss.elastic.co/t/a-user-who-can-create-delete-their-indexes-but-restricted-to-deleting-others/351296/3 "2024-01-22T13:35:39Z")

</div>

Thanks @jessgarson I will explore the page. But is there any role which could have those privileges with included maybe? Apologies for a late reply

---

<div class="post-metadata">

**Author:** ![leandrojmp](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/leandrojmp/32/107231_2.png) [@leandrojmp](https://discuss.elastic.co/u/leandrojmp)\
**Post date:** [January 22, 2024, 1:40pm UTC](https://discuss.elastic.co/t/a-user-who-can-create-delete-their-indexes-but-restricted-to-deleting-others/351296/4 "2024-01-22T13:40:54Z")

</div>

> [@jeannshuti](#):
>
> But is there any role which could have those privileges with included maybe?

I don't think there any specific in Elasticsearch that would do that.

You can create a custom role to do what you want, but you will also need that each user index uses a prefix or sufix so this can be added to the role, which also means that you will need one role per user.

For example, your users would need to use index like this: `username-index-name` or `index-name-username`, then you would create a role that gives full access to the index `username-*` for the specific user.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [February 19, 2024, 1:41pm UTC](https://discuss.elastic.co/t/a-user-who-can-create-delete-their-indexes-but-restricted-to-deleting-others/351296/5 "2024-02-19T13:41:40Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
