Role-based access control (RBAC)

RBAC applies to multi-user authentication

Role-based access control governs users signed in through multi-user authentication, which is off by default in InfluxDB 3 Enterprise. Existing apiv3_ token workflows are unaffected. See Manage users and authentication to enable it.

Role-based access control (RBAC) governs what authenticated users can do in InfluxDB 3 Enterprise. Each user is assigned one or more built-in roles that determine their permissions.

Built-in roles

InfluxDB 3 Enterprise provides three built-in roles:

  • Admin: Full access to all resources, including creating and managing other users, roles, and tokens.
  • Auditor: Can list and describe databases and read tokens, users, and roles. Can’t query or write data.
  • Member: Can query and write data and create databases, and can create, read, and delete tokens. Can read users and roles. Can’t delete databases or manage users, roles, or admin tokens.

Auditor and Member grant less than their names suggest

Only the Admin role (or an admin token) has full access. The Auditor role can’t read data, and neither Auditor nor Member can access system endpoints such as /health, /metrics, /ping, and /ready, or query the _internal database. Use an admin token for user and role management.

Assign roles

Assign roles to a user with the influxdb3 update user-roles command. See Manage users and authentication for the user-management workflow.

Custom roles

Authoring custom roles (creating roles and editing role permissions) is disabled by default (--rbac-authoring-disabled defaults to true). Listing roles and assigning the built-in roles to users remain available regardless of this setting. See configuration options for details.

Limitations

RBAC has the following known limitation in InfluxDB 3 Enterprise:

  • Token scope can exceed role scope: A user with token-creation permission (Admin or Member) can create a token with database-level permissions broader than their own role. InfluxDB 3 Enterprise only restricts non-admin users from creating tokens that grant system-resource permissions.

Was this page helpful?

Thank you for your feedback!