# Read-only user - what is it?

**URL:** <https://discourse.nodered.org/t/read-only-user-what-is-it/72765>\
**Category:** Core Development\
**Created:** [27 December 2022 11:55 UTC](https://discourse.nodered.org/t/read-only-user-what-is-it/72765 "2022-12-27T11:55:29Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![alex.mpplabs](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/alex.mpplabs/32/73341_2.png) [@alex.mpplabs](https://discourse.nodered.org/u/alex.mpplabs)\
**Post date:** [27 December 2022 11:55 UTC](https://discourse.nodered.org/t/read-only-user-what-is-it/72765/1 "2022-12-27T11:55:29Z")

</div>

During our investigation of Node Red we have found a user with read-only access. There is a couple of questions:

1. Is there any use case for this user? In the other words, is there any examples in what situations this user is needed?

2. Can we modify read-only users in order to allow them to create flows in their isolated sandboxes, while admin user can see it?

---

<div class="post-metadata">

**Author:** ![Colin](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/colin/32/17040_2.png) [@Colin](https://discourse.nodered.org/u/Colin)\
**Post date:** [27 December 2022 12:48 UTC](https://discourse.nodered.org/t/read-only-user-what-is-it/72765/2 "2022-12-27T12:48:10Z")

</div>

Where are you seeing this user?

---

<div class="post-metadata">

**Author:** ![knolleary](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/knolleary/32/3_2.png) [@knolleary](https://discourse.nodered.org/u/knolleary)\
**Post date:** [27 December 2022 13:39 UTC](https://discourse.nodered.org/t/read-only-user-what-is-it/72765/3 "2022-12-27T13:39:06Z")

</div>

Hi @alex.mpplabs

> [@alex.mpplabs](#):
>
> we have found a user with read-only access.

This section of the docs describes how you can configure users and their permissions: [Securing Node-RED : Node-RED](https://nodered.org/docs/user-guide/runtime/securing-node-red#editor--admin-api-security)

> [@alex.mpplabs](#):
>
> Is there any use case for this user? In the other words, is there any examples in what situations this user is needed?

If you want to have a user who can view the flows but not make any changes. For example, I want to show you my flows, but not let you make any changes.

Nothing requires you to have a read-only user if you don't have a need for one.

> [@alex.mpplabs](#):
>
> Can we modify read-only users in order to allow them to create flows in their isolated sandboxes, while admin user can see it?

If the user can make changes, they aren't a read-only user any more. As per the docs I linked to above, you can configure multiple users with read-write access in whatever way you want.

> [@alex.mpplabs](#):
>
> allow them to create flows in their isolated sandboxes

The Node-RED runtime is single-tenant. Whilst you may have multiple users able to access the editor, they are working on the same set of flows. There is no 'isolated sandbox' within Node-RED.

There are some 3rd-party platforms that make it easier to manage multiple users across multiple instances of Node-RED, with different levels of access control. For example [FlowForge](https://flowforge.com) - (disclosure: when I'm not running the Node-RED project, I'm the CTO/Founder of FlowForge). It depends on what your specific requirements are.

---

<div class="post-metadata">

**Author:** ![alex.mpplabs](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/alex.mpplabs/32/73341_2.png) [@alex.mpplabs](https://discourse.nodered.org/u/alex.mpplabs)\
**Post date:** [28 December 2022 07:14 UTC](https://discourse.nodered.org/t/read-only-user-what-is-it/72765/4 "2022-12-28T07:14:31Z")

</div>

Hi Nick!

Thanks for your answer.

We are actually planning to implement multitenancy in Node Red for the whole community in the beginning of 2023. If you'd like to join the effort, that would be great.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/flex026/uploads/nodered/original/1X/d073cd938eafa2e558d7c2cd59003b3ef4963033.png) [@system](https://discourse.nodered.org/u/system)\
**Post date:** [26 February 2023 07:14 UTC](https://discourse.nodered.org/t/read-only-user-what-is-it/72765/5 "2023-02-26T07:14:37Z")

</div>

This topic was automatically closed 60 days after the last reply. New replies are no longer allowed.
