elastic / elastic/roadmap

Restrict Cloud Console access for data-only users

Open
#379 0 comments 0 reactions 1 assignee Claimed by @alxchalkias View on GitHub
Component: Elastic Cloud Serverless product-area:platform
Dominant language
No language data
Stars
6
Forks
1
PR merge metrics
No merged PRs in 30d

Description

**What the feature is**

Restrict Cloud Console access for data-only users on Elastic Cloud Serverless.

Organization admins can assign members a per-project **Elasticsearch and Kibana** access level so those users work in their project's data plane without seeing org-level Cloud Console surfaces, such as Members, Billing, Trust Management, Extensions, and other projects. This is for enterprises, centers of excellence, and MSPs whose end users, analysts, or contractors need Kibana and Elasticsearch but should not manage or browse the Cloud organization.

**Value proposition**

On Serverless, every user signs in through the Cloud organization, so today anyone can open [cloud.elastic.co](https://cloud.elastic.co) and land on admin-oriented pages, even when their role is scoped to a single project. In multi-tenant setups, that exposes org navigation and can leak other tenants' member information. Customers describe this as overexposure and a Serverless adoption blocker.

This feature confines data-only users to their projects: Cloud Console URLs and common in-product links that jump to the Console resolve to a clear access-denied experience instead of a partial or confusing console. Admins can provision the access level at scale through the same role-assignment paths they already use (including SSO role mapping and automation).

**Expected outcome**

- Admins choose **Elasticsearch and Kibana** (data plane only) vs full Cloud Console access when assigning roles to organization members.
- Data-only users open their project via project URLs and do not use the Cloud Console for day-to-day work.
- Attempts to open Cloud Console URLs show an access-denied message.
- Organization owners can see who has full Console access vs data-plane-only on the Members page.
- Multi-organization membership continues to work: restrictions apply per organization; users can still switch orgs where they belong.
- Initial delivery targets **Elastic Cloud Serverless** (ECH deployment-level sign-in already offers a different path for many end users).

Contributor guide

No contributing guide indexed for this repository

Assessment

This issue has not been assessed yet.

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.