# Add user role in ECE or revoke access on "client"

**URL:** <https://discuss.elastic.co/t/add-user-role-in-ece-or-revoke-access-on-client/299705>\
**Category:** Elastic Cloud Enterprise (ECE)\
**Created:** [March 15, 2022, 9:17am UTC](https://discuss.elastic.co/t/add-user-role-in-ece-or-revoke-access-on-client/299705 "2022-03-15T09:17:41Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![stobbe99](https://avatars.discourse-cdn.com/v4/letter/s/bc8723/32.png) [@stobbe99](https://discuss.elastic.co/u/stobbe99)\
**Post date:** [March 15, 2022, 9:17am UTC](https://discuss.elastic.co/t/add-user-role-in-ece-or-revoke-access-on-client/299705/1 "2022-03-15T09:17:42Z")

</div>

Hello,

Is is possible to add additional roles in ECE and is it possible to revoke the ECE accounts on created environments.

As a use case, from ECE we create environments for different customers. There are customers who really like to know who has what access to their environment,

KR Henk

---

<div class="post-metadata">

**Author:** ![Daniel\_Battaglia](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/daniel_battaglia/32/49649_2.png) [@Daniel\_Battaglia](https://discuss.elastic.co/u/Daniel_Battaglia)\
**Post date:** [March 15, 2022, 10:45am UTC](https://discuss.elastic.co/t/add-user-role-in-ece-or-revoke-access-on-client/299705/2 "2022-03-15T10:45:03Z")

</div>

It is not possible to add additional / custom roles in ECE, there are just the 4 documented roles (platform admin / view and deployment manager / viewer). It sounds like for your use case you would only want to apply the Deployment Manager and Deployment Viewer roles, and not let these customers have Platform level roles (to avoid access to Runners/ Allocators / system clusters / etc).

It is possible to revoke "native" users by either deleting them or disabling them. The "disable" feature is only available [via the API](https://www.elastic.co/guide/en/cloud-enterprise/current/update-user.html):

```auto
curl $ECE_URL/api/v1/users/$USERNAME -u admin:$PW \
  -XPATCH -H 'content-type: application/json' \
  -d '{ "security": { "enabled": false } }'

```

(and you can call again with `"enabled": true` to enable them again).

Note that Native users can create API keys, and disabling the user will not disable their keys, you must revoke those separately (in the UI or via the API).

Worth mentioning that it is also possible to [configure ECE to log in via SAML, LDAP or Active Directory](https://www.elastic.co/guide/en/cloud-enterprise/current/ece-configure-rbac.html), and use role mappings to assign users to roles. This might be a more convenient way to manage users if you have a large number of customers compared to using "native" ECE users. The same caveats apply regarding API keys, they must be revoked separately.

---

<div class="post-metadata">

**Author:** ![stobbe99](https://avatars.discourse-cdn.com/v4/letter/s/bc8723/32.png) [@stobbe99](https://discuss.elastic.co/u/stobbe99)\
**Post date:** [March 15, 2022, 11:50am UTC](https://discuss.elastic.co/t/add-user-role-in-ece-or-revoke-access-on-client/299705/3 "2022-03-15T11:50:57Z")

</div>

Perfect, thanks for your great reply!

KR Henk 👍

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [March 29, 2022, 11:51am UTC](https://discuss.elastic.co/t/add-user-role-in-ece-or-revoke-access-on-client/299705/4 "2022-03-29T11:51:11Z")

</div>

This topic was automatically closed 14 days after the last reply. New replies are no longer allowed.
