# Enquiry about X-Pack Role Based Control for Documents

**URL:** <https://discuss.elastic.co/t/enquiry-about-x-pack-role-based-control-for-documents/110961>\
**Category:** Elasticsearch\
**Created:** [December 10, 2017, 9:28am UTC](https://discuss.elastic.co/t/enquiry-about-x-pack-role-based-control-for-documents/110961 "2017-12-10T09:28:17Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![Ong](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ong/32/40766_2.png) [@Ong](https://discuss.elastic.co/u/Ong)\
**Post date:** [December 10, 2017, 9:28am UTC](https://discuss.elastic.co/t/enquiry-about-x-pack-role-based-control-for-documents/110961/1 "2017-12-10T09:28:17Z")

</div>

I am looking at implementing role based access control using X-Pack on a document level. From the documentation, a role could be defined for my document like this:

```auto
{ "indices": [{ "names": [ "events-*"], "privileges": ["read"], "query": "{"term": {"tags": "blog","sub-tags": "games","year": 2017 }}" } ]
}

```

For the query part, is it possible to extract the attributes "sub-tags" and "year" and place them in a template like Year\_Game so that the query becomes like this:

```auto
{ "indices": [{ "names": [ "events-*"], "privileges": ["read"], "query": "{"term": {"tags": "blog","Year_Game.sub-tags": "games","Year_Game.year": 2017 }}" } ]
}

```

The purpose is to simplify the administrator's task of creating roles so that they can simply re-use existing templates to create new roles.

How could I do this in X-pack?

---

<div class="post-metadata">

**Author:** ![TimV](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/timv/32/13162_2.png) [@TimV](https://discuss.elastic.co/u/TimV)\
**Post date:** [December 11, 2017, 5:01am UTC](https://discuss.elastic.co/t/enquiry-about-x-pack-role-based-control-for-documents/110961/2 "2017-12-11T05:01:28Z")

</div>

You cannot do this out of the box, but there's a few options that might work.

The query can be [templated by metadata stored on the user](https://www.elastic.co/guide/en/x-pack/6.0/field-and-document-access-control.html#templating-role-query), so if you're able to manage the "Year\_Game" on the user, it could work:

```auto
"query": {
   "template": {
      "source": {
          "term": {
              "tags": "blog",
              "{{_user.metadata.Year_Game}}.sub-tags": "games",
              "{{_user.metadata.Year_Game}}.year": 2017 }}
      }
   }
}

```

I'm not 100% sure I provided the example you want though - I'm a little confused about your example and what you want to template.

_Alternatively_, you can implement custom roles providers, so if you wanted to, you could just do all this in code, or pull your role definitions from an external system.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [January 8, 2018, 5:01am UTC](https://discuss.elastic.co/t/enquiry-about-x-pack-role-based-control-for-documents/110961/3 "2018-01-08T05:01:43Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
