# ECE role-based access control

**URL:** <https://discuss.elastic.co/t/ece-role-based-access-control/198286>\
**Category:** Elastic Cloud Enterprise (ECE)\
**Created:** [September 5, 2019, 3:47pm UTC](https://discuss.elastic.co/t/ece-role-based-access-control/198286 "2019-09-05T15:47:52Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![ippolito](https://avatars.discourse-cdn.com/v4/letter/i/8edcca/32.png) [@ippolito](https://discuss.elastic.co/u/ippolito)\
**Post date:** [September 5, 2019, 3:47pm UTC](https://discuss.elastic.co/t/ece-role-based-access-control/198286/1 "2019-09-05T15:47:52Z")

</div>

All - I'm trying to script putting an allocator into maintenance mode, but I don't want to use platform admin privileges. I read this document:

[https://www.elastic.co/guide/en/cloud-enterprise/current/ece-configure-rbac.html](https://www.elastic.co/guide/en/cloud-enterprise/current/ece-configure-rbac.html)

which says "there are several pre-built roles," implying you might be able to customize access control. But I see no way to do that. Wondering if there's a way to grant a user _only_ the permission to put a node into maintenance mode (and to take it back out again).

Thanks in advance,  
Mike

---

<div class="post-metadata">

**Author:** ![Alex\_Piggott](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/alex_piggott/32/11053_2.png) [@Alex\_Piggott](https://discuss.elastic.co/u/Alex_Piggott)\
**Post date:** [September 5, 2019, 5:54pm UTC](https://discuss.elastic.co/t/ece-role-based-access-control/198286/2 "2019-09-05T17:54:22Z")

</div>

Unfortunately custom roles is not a supported feature until a future phase ☹

With ECE It's currently necessary to do grovelly things like expose desired endpoints via separately authenticated services (eg nginx). We appreciate that this isn't great and we're working toward doing it properly (but multi-user + multi-org will come first)

If you raise a support ticket you can get your friendly support rep to vote for this feature via our internal "enhancement request" mechanism, which helps drive the priorities within our engineering roadmap

Alex

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [September 19, 2019, 6:01pm UTC](https://discuss.elastic.co/t/ece-role-based-access-control/198286/3 "2019-09-19T18:01:38Z")

</div>

This topic was automatically closed 14 days after the last reply. New replies are no longer allowed.
