# Assign users to APM Agents

**URL:** <https://discuss.elastic.co/t/assign-users-to-apm-agents/340623>\
**Category:** Elastic Observability\
**Created:** [August 11, 2023, 8:00am UTC](https://discuss.elastic.co/t/assign-users-to-apm-agents/340623 "2023-08-11T08:00:09Z")\
**Posts on this page:** 1\
**Page:** 1

<div class="post-metadata">

**Author:** ![Namita\_Jaokar](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/namita_jaokar/32/104106_2.png) [@Namita\_Jaokar](https://discuss.elastic.co/u/Namita_Jaokar)\
**Post date:** [August 11, 2023, 8:00am UTC](https://discuss.elastic.co/t/assign-users-to-apm-agents/340623/1 "2023-08-11T08:00:09Z")

</div>

Hi All,

I am using ELK Version 8.6.2 and trying to create separate users for different Java APM Agents.  
For Example If I have 2 APM Agents namely 1\_agent & 2\_agent and 2 Users User1 and User2.

My requirement is such that User1 can only perform operations and view data for 1\_agent. While User2 can do the same for 2\_agent.  
Both User1 and User2 cannot view each others agent or any other data.

For the same, I have tried creating space and roles and then assigning users to that roles but that did not work.

I have also tried adding indices , in the index privilege option of the roles. Below is the snip of the same

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/4/7/47d6cbb01221bae6a9dbf88a76fae61016dbbf6f.png)

But above also did not work probably because such indices do not exist. Below is the output I get when I try to cat the indices  
 ![image](https://us1.discourse-cdn.com/elastic/original/3X/5/b/5b1d18e574f05f82e456c8e5b569d86b8a5280eb.png)

Please suggest me a correct way of implementing user based APM agent traces  
I also came across below Issue in elastic discussions:

> [@Restrict Kibana users to only see some APM service.environment in APM UI](https://discuss.elastic.co/t/restrict-kibana-users-to-only-see-some-apm-service-environment-in-apm-ui/227784):
>
> Hi, I would like to ask if there is a way to config Kibana's APM UI to restrict users to only see some environment in ELK 6.8? for example I have 3 APM indexes which are \*-apm-\* foo-bar-apm-\* jane-doe-apm-\* these indexes getting data from 2 Java Apm-Agent's environment configuration which are sending to the same APM server as below service.environment : foo-bar service.environment: jane-doe I configured Kibana config as below for APM UI apm\_oss: indexPattern: "\*-apm-\*" erro…

But unable to view this option anywhere in the role privileges.

**NOTE** : _ **Both agents point to the same apm-server** _

Kindly advise.

Best Regards,  
Namita Jaokar
