# Adding new user in role mapping

**URL:** <https://discuss.elastic.co/t/adding-new-user-in-role-mapping/339755>\
**Category:** Elasticsearch\
**Tags:** elastic-stack-security\
**Created:** [August 1, 2023, 7:06am UTC](https://discuss.elastic.co/t/adding-new-user-in-role-mapping/339755 "2023-08-01T07:06:30Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![Ganesh2303](https://avatars.discourse-cdn.com/v4/letter/g/57b2e6/32.png) [@Ganesh2303](https://discuss.elastic.co/u/Ganesh2303)\
**Post date:** [August 1, 2023, 7:06am UTC](https://discuss.elastic.co/t/adding-new-user-in-role-mapping/339755/1 "2023-08-01T07:06:31Z")

</div>

HI Team,  
I'm trying to add new user in my existing role mapping and when i perform the action it delete all the existing user from it and create the new user which im parsing.

I need to append this in my existing role mapping and how to achieve it.

> POST /\_security/role\_mapping/elk\_admin\_team\_test  
> {  
> "roles": ["superuser"],  
> "enabled": true,  
> "rules": {  
> "field" : { "username" : "ganesh" }  
> },  
> "metadata" : {  
> "version" : 1  
> }  
> }

---

<div class="post-metadata">

**Author:** ![sholzhauer](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/sholzhauer/32/110282_2.png) [@sholzhauer](https://discuss.elastic.co/u/sholzhauer)\
**Post date:** [August 1, 2023, 9:03am UTC](https://discuss.elastic.co/t/adding-new-user-in-role-mapping/339755/2 "2023-08-01T09:03:06Z")

</div>

Hi,

This is because the update of a role mapping does not "add" but "overwrites", you use the api to define how it should look, no matter of the current state.

I also responded to your [question about removing users](https://discuss.elastic.co/t/how-to-remove-a-user-from-role-mapping/339688/4); You can use the same approach here by first retrieving the current implementation and then updating it with the desired set.

Another approach you could take is to use [Terraform](https://registry.terraform.io/providers/elastic/elasticstack/latest/docs/resources/elasticsearch_security_role_mapping) if you are familiar, it can handle the logic for you.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [August 29, 2023, 9:03am UTC](https://discuss.elastic.co/t/adding-new-user-in-role-mapping/339755/3 "2023-08-29T09:03:54Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
