Security

Delete the roles power and user

reed_kelly
Contributor

I define specific roles for each team. I don't particularly see a use for the Power or User roles. In fact, I find it annoying that "power" is added to app modify rights, by default. Are there any side effects of deleting these two roles to prevent their accidental use?

Tags (1)
0 Karma

sduff_splunk
Splunk Employee
Splunk Employee

In general, most other roles will inherit the permissions and capabilities from the user role (some elevated roles would use power), so I would strongly advise against removing the user and power roles.

reed_kelly
Contributor

I specifically create new base roles to inherit from. For example, I create a base_user with no data access and some basic search capabilities. I also create a base_dev role with additional capabilities for editing dashboards and scheduling searches. My goal is to lock down access to "least required" by each team to meet audit guidelines. I am not seeing any inherited features of user or power in my other roles. Are there any hidden attributes that are inherited from user or power?

0 Karma
Get Updates on the Splunk Community!

Splunk Decoded: Service Maps vs Service Analyzer Tree View vs Flow Maps

It’s Monday morning, and your phone is buzzing with alert escalations – your customer-facing portal is running ...

What’s New in Splunk Observability – September 2025

What's NewWe are excited to announce the latest enhancements to Splunk Observability, designed to help ITOps ...

Fun with Regular Expression - multiples of nine

Fun with Regular Expression - multiples of nineThis challenge was first posted on Slack #regex channel ...