# Permission to give permission to Indices

**URL:** <https://discuss.elastic.co/t/permission-to-give-permission-to-indices/262253>\
**Category:** Elasticsearch\
**Tags:** elastic-stack-security\
**Created:** [January 26, 2021, 4:01pm UTC](https://discuss.elastic.co/t/permission-to-give-permission-to-indices/262253 "2021-01-26T16:01:50Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![Zerobot](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/zerobot/32/48977_2.png) [@Zerobot](https://discuss.elastic.co/u/Zerobot)\
**Post date:** [January 26, 2021, 4:01pm UTC](https://discuss.elastic.co/t/permission-to-give-permission-to-indices/262253/1 "2021-01-26T16:01:50Z")

</div>

Hi!  
I was wondering - is it possible to give someone permission to read some indices AND also a permission to give read-only permissions to other users?

My point is: I have 5 indices and 5 people, each person has permissions to read only 1 index and I'd like to let this person be in charge of who reads their index and who can't.

---

<div class="post-metadata">

**Author:** ![elasticforme](https://avatars.discourse-cdn.com/v4/letter/e/f05b48/32.png) [@elasticforme](https://discuss.elastic.co/u/elasticforme)\
**Post date:** [January 26, 2021, 7:24pm UTC](https://discuss.elastic.co/t/permission-to-give-permission-to-indices/262253/2 "2021-01-26T19:24:06Z")

</div>

yes you can do that.

you have to look in to space, roles and user

here is example  
index1 -\> user1 -\> space1 -\> role1

first create space1.  
second create role1 and assign space1 to it  
third create user1 and assign role1

---

<div class="post-metadata">

**Author:** ![Zerobot](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/zerobot/32/48977_2.png) [@Zerobot](https://discuss.elastic.co/u/Zerobot)\
**Post date:** [January 27, 2021, 4:47pm UTC](https://discuss.elastic.co/t/permission-to-give-permission-to-indices/262253/3 "2021-01-27T16:47:02Z")

</div>

Sorry but I don't understand - which roles/permissions should I give to user1 in space1 so he will be able to also give permissions to other users but, not like, superuser permissions?

I've tested your example and it seemed I had to give "security manager" role to the user, for him to be able to give permissions to others. But if he has the "security manager" role he can also give himself "superuser" role straight away and that's a bad idea.

---

<div class="post-metadata">

**Author:** ![elasticforme](https://avatars.discourse-cdn.com/v4/letter/e/f05b48/32.png) [@elasticforme](https://discuss.elastic.co/u/elasticforme)\
**Post date:** [January 27, 2021, 6:22pm UTC](https://discuss.elastic.co/t/permission-to-give-permission-to-indices/262253/4 "2021-01-27T18:22:40Z")

</div>

not that I have no clue.  
someone else might know

---

<div class="post-metadata">

**Author:** ![TimV](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/timv/32/13162_2.png) [@TimV](https://discuss.elastic.co/u/TimV)\
**Post date:** [January 29, 2021, 5:57am UTC](https://discuss.elastic.co/t/permission-to-give-permission-to-indices/262253/5 "2021-01-29T05:57:07Z")

</div>

No, it is not possible to manage Elasticsearch permissions in that way.

Because ES security is built on a role based model, the only way to give a user the ability to read from an index is to modify one or more roles that are held by the target user.  
A user who can modify roles can make any/all changes they wish to those roles - they cannot be restricted to only granting a particular level of access to particular indices.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [February 26, 2021, 5:57am UTC](https://discuss.elastic.co/t/permission-to-give-permission-to-indices/262253/6 "2021-02-26T05:57:23Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
