Map Elastic Cloud roles with Elastic Stack rolesedit

Kibana users and organization members are not a 1:1 relationship. All members of the organization are users of the deployment, but not all the deployment users are members of the organization. The deployment users that login with Elasticsearch credentials are not members of the organization, unless they have the cloud.elastic.co credentials.

Cloud roles are mapped to Stack roles on a per-deployment level. When logging into a specific deployment, users get the Stack role that maps to their Cloud role for that particular deployment.

The following table shows the default mapping:

Cloud role

Stack role

Organization owner

superuser

Billing admin

none

Deployment admin

superuser

Deployment editor

editor

Deployment viewer

viewer

This table applies to Elasticsearch versions from 7.13 onwards. For earlier versions, only the superuser role mapping applies.