# Explanation of the cluster and indices actions privileges

**URL:** <https://discuss.elastic.co/t/explanation-of-the-cluster-and-indices-actions-privileges/42269>\
**Category:** Elasticsearch\
**Tags:** elastic-stack-security\
**Created:** [February 19, 2016, 6:32pm UTC](https://discuss.elastic.co/t/explanation-of-the-cluster-and-indices-actions-privileges/42269 "2016-02-19T18:32:29Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![ksoucy](https://avatars.discourse-cdn.com/v4/letter/k/dc4da7/32.png) [@ksoucy](https://discuss.elastic.co/u/ksoucy)\
**Post date:** [February 19, 2016, 6:32pm UTC](https://discuss.elastic.co/t/explanation-of-the-cluster-and-indices-actions-privileges/42269/1 "2016-02-19T18:32:29Z")

</div>

Is there a document that details what each of the cluster/indices actions privileges will allow/not allow in Kibana and ES ? Its difficult to properly set up roles when its not really clear what the individual privileges mean. Using Shield 2.1.1, ES 2.1.1, Kibana 4.3.1. Thks

---

<div class="post-metadata">

**Author:** ![jaymode](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jaymode/32/50103_2.png) [@jaymode](https://discuss.elastic.co/u/jaymode)\
**Post date:** [February 22, 2016, 6:52pm UTC](https://discuss.elastic.co/t/explanation-of-the-cluster-and-indices-actions-privileges/42269/2 "2016-02-22T18:52:10Z")

</div>

Hi Kevin,

We do not currently have a document that details what all of the action privileges allow. These map to the names of the actions user elasticsearch, for example the action name here [https://github.com/elastic/elasticsearch/blob/2.2/core/src/main/java/org/elasticsearch/action/search/SearchAction.java#L30](https://github.com/elastic/elasticsearch/blob/2.2/core/src/main/java/org/elasticsearch/action/search/SearchAction.java#L30) maps to the operations performed by a matching transport action [https://github.com/elastic/elasticsearch/blob/2.2/core/src/main/java/org/elasticsearch/action/search/TransportSearchAction.java](https://github.com/elastic/elasticsearch/blob/2.2/core/src/main/java/org/elasticsearch/action/search/TransportSearchAction.java)

Do you have a need to secure down to the specific actions or will the `read`, `write`, etc group privileges work for your use case? If they are not sufficient, are there specific ones that you have questions about?

---

<div class="post-metadata">

**Author:** ![ksoucy](https://avatars.discourse-cdn.com/v4/letter/k/dc4da7/32.png) [@ksoucy](https://discuss.elastic.co/u/ksoucy)\
**Post date:** [February 22, 2016, 7:31pm UTC](https://discuss.elastic.co/t/explanation-of-the-cluster-and-indices-actions-privileges/42269/3 "2016-02-22T19:31:39Z")

</div>

Hi Jay, the "read" and "all" options are currently working for us, but before we open Kibana up to additional clients I was trying to find that sweet spot where we could allow users to create searches, visualizations, dashboards, etc, but perhaps not overwrite (or delete) existing objects. Unfortunately since ES and/or Kibana dont protect objects on a "user who created" basis, then anyone with write/all for an index can mistakenly delete or chg objects someone else created in that index. This is, unless i'm missing something and there is a clear way of doing this?

Thks for your feedback.

---

<div class="post-metadata">

**Author:** ![jaymode](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jaymode/32/50103_2.png) [@jaymode](https://discuss.elastic.co/u/jaymode)\
**Post date:** [February 22, 2016, 8:34pm UTC](https://discuss.elastic.co/t/explanation-of-the-cluster-and-indices-actions-privileges/42269/4 "2016-02-22T20:34:58Z")

</div>

> [@ksoucy](#):
>
> Unfortunately since ES and/or Kibana dont protect objects on a "user who created" basis, then anyone with write/all for an index can mistakenly delete or chg objects someone else created in that index

You are correct, we do not have this capability with Shield and Kibana today and realize that this is something a lot of our users need. We are working on adding capabilities to support this.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 6, 2017, 1:46pm UTC](https://discuss.elastic.co/t/explanation-of-the-cluster-and-indices-actions-privileges/42269/5 "2017-07-06T13:46:35Z")

</div>


