Map Elastic Cloud roles with Elastic Stack rolesedit

Kibana users and organization members are not a 1:1 relationship. All members of the organization are users of the deployment, but not all the deployment users are members of the organization. The deployment users that login with Elasticsearch credentials are not members of the organization, unless they have the cloud.elastic.co credentials.

Cloud roles are mapped to Stack roles on a per-deployment level. When logging into a specific deployment, users get the Stack role that maps to their Cloud role for that particular deployment.

The following table shows the default mapping:

Cloud role

Stack role

Organization owner

superuser

Billing admin

none

Admin

superuser

Editor

editor

Viewer

viewer

This table applies to Elasticsearch versions from 7.13 onwards. For earlier versions, only the superuser role mapping applies.