Map Elastic Cloud roles with Elastic Stack roles

Kibana users and organization members are not a 1:1 relationship. All members of the organization are users of the deployment, but not all the deployment users are members of the organization. The deployment users that login with Elasticsearch credentials are not members of the organization, unless they have the credentials.

Cloud roles are mapped to Stack roles on a per-deployment level. When logging into a specific deployment, users get the Stack role that maps to their Cloud role for that particular deployment.

The following table shows the default mapping:

Cloud role

Stack role

Organization owner


Billing admin


Deployment admin


Deployment editor


Deployment viewer


This table applies to Elasticsearch versions from 7.13 onwards. For earlier versions, only the superuser role mapping applies.