# Access control about the watcher

**URL:** <https://discuss.elastic.co/t/access-control-about-the-watcher/159315>\
**Category:** Elasticsearch\
**Tags:** elastic-stack-alerting\
**Created:** [December 4, 2018, 9:10am UTC](https://discuss.elastic.co/t/access-control-about-the-watcher/159315 "2018-12-04T09:10:33Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![talon](https://avatars.discourse-cdn.com/v4/letter/t/c77e96/32.png) [@talon](https://discuss.elastic.co/u/talon)\
**Post date:** [December 4, 2018, 9:10am UTC](https://discuss.elastic.co/t/access-control-about-the-watcher/159315/1 "2018-12-04T09:10:33Z")

</div>

HI  
I want to assign user the permission to create watcher and read watcher, and have no permission to delete it. can you tell me how to configure the roles. below is my configuration, but the user not only can create the watcher but also can delete it.  
POST /\_xpack/security/role/test\_power\_role  
{  
"cluster": ["monitor"],  
"indices": [  
{  
"names": ["telemetry\_processing\_eventflow\*"],  
"privileges":[  
"manage",  
"read",  
"index"  
]  
},  
{  
"names": [  
".kibana\*"  
],  
"privileges": [  
"manage",  
"read",  
"index"  
]  
},  
{  
"names": [  
".watches"  
],  
"privileges": [  
"read",  
"create"  
]  
}  
]  
}

PUT /\_xpack/security/role\_mapping/test\_power\_mapping  
{  
"roles": ["test\_power\_role","monitoring\_user" ,"watcher\_admin"],  
"enabled": true,  
"rules": {  
"field": { "metadata.saml(Group)": "corp.elasticsearch.test" }  
}  
}  
the elasticsearch version is 6.3.1

---

<div class="post-metadata">

**Author:** ![spinscale](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/spinscale/32/25011_2.png) [@spinscale](https://discuss.elastic.co/u/spinscale)\
**Post date:** [December 7, 2018, 9:08am UTC](https://discuss.elastic.co/t/access-control-about-the-watcher/159315/2 "2018-12-07T09:08:44Z")

</div>

Instead of using the `watcher_admin` role, you could allow for fine grained permissions on a transport action base like allowing for `cluster:admin/xpack/watcher/watch/put` but not allowing for `cluster:admin/xpack/watcher/watch/delete`.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [January 4, 2019, 9:09am UTC](https://discuss.elastic.co/t/access-control-about-the-watcher/159315/3 "2019-01-04T09:09:16Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
