[GH-ISSUE #5566] allow user level access right #11750

Open
opened 2026-08-05 01:30:49 -04:00 by saavagebueno · 1 comment
Owner

Originally created by @IzunaMoon on GitHub (Mar 10, 2026).
Original GitHub issue: https://github.com/netbirdio/netbird/issues/5566

Is your feature request related to a problem? Please describe.
At the moment I have an issue where I'd love to just say "this user has access to these devices." Currently I have a lot of groups with only 1 user, just so that when a user logs in they automatically get access to those resources.

I don't really allow peer-to-peer communication in my policies, only resources. While groups work well for larger teams, in cases where just 1 person needs access to certain resources, or just a few people, it becomes a lot to manage quite fast.

Describe the solution you'd like
allow user level setup in policy where we can just say this user can access this resource

Image

Describe alternatives you've considered
not really any other easy solution in mind

Additional context
i dont know if this is possible but if possible it will make things so much more cleaner in groups

than we can just have groups for hour deparment en than if spesific access is needed like ssh to spesific vm for axample a external company tah nwe can just say dat user can access sins in many cases external compaies share 1 account not mutiple for company

here is a axample for how i will love to setup de policy

Image
Originally created by @IzunaMoon on GitHub (Mar 10, 2026). Original GitHub issue: https://github.com/netbirdio/netbird/issues/5566 **Is your feature request related to a problem? Please describe.** At the moment I have an issue where I'd love to just say "this user has access to these devices." Currently I have a lot of groups with only 1 user, just so that when a user logs in they automatically get access to those resources. I don't really allow peer-to-peer communication in my policies, only resources. While groups work well for larger teams, in cases where just 1 person needs access to certain resources, or just a few people, it becomes a lot to manage quite fast. **Describe the solution you'd like** allow user level setup in policy where we can just say this user can access this resource <img width="507" height="91" alt="Image" src="https://github.com/user-attachments/assets/d081293d-c9e2-4bf7-9daa-4cf356e84ff8" /> **Describe alternatives you've considered** not really any other easy solution in mind **Additional context** i dont know if this is possible but if possible it will make things so much more cleaner in groups than we can just have groups for hour deparment en than if spesific access is needed like ssh to spesific vm for axample a external company tah nwe can just say dat user can access sins in many cases external compaies share 1 account not mutiple for company here is a axample for how i will love to setup de policy <img width="1646" height="69" alt="Image" src="https://github.com/user-attachments/assets/564c358a-4e75-4a03-b9e5-cbb8a0d0eb72" />
saavagebueno added the feature-request label 2026-08-05 01:30:49 -04:00
Author
Owner

@IzunaMoon commented on GitHub (Mar 10, 2026):

ps im aware you can use de grou users but this give every users access to dat resource with is not de goal

as mention ad de moment i make a user tan a group call UG-Username a than in policy put de group UG-Group this works but it just makes a lot off groups to manage when you can just easy say allow this user to access this

this also add de added beneifit dat you can put all auto assing groups get put in de users group

Image

just set this to users a you can easy filter wat devices are other people devices just by going to groups a select peers users than you get a list off all user devices a not your company resources if yo uput dat in a diffrent group

Image

or kust replace de auto assinged groups witg user groups a have automatl be devices be put on users

it are jsut osme ideas de tool work great like it is but i do have to do some work arounds to get it working for hour needs it works but it be a very nice to have

you can see your self how intresting this idea is
sins than it create differnt levels
user level access
group level access

<!-- gh-comment-id:4031481618 --> @IzunaMoon commented on GitHub (Mar 10, 2026): ps im aware you can use de grou users but this give every users access to dat resource with is not de goal as mention ad de moment i make a user tan a group call UG-Username a than in policy put de group UG-Group this works but it just makes a lot off groups to manage when you can just easy say allow this user to access this this also add de added beneifit dat you can put all auto assing groups get put in de users group <img width="678" height="380" alt="Image" src="https://github.com/user-attachments/assets/f439ff34-f3e7-4999-b707-4b2fd2594dad" /> just set this to users a you can easy filter wat devices are other people devices just by going to groups a select peers users than you get a list off all user devices a not your company resources if yo uput dat in a diffrent group <img width="678" height="380" alt="Image" src="https://github.com/user-attachments/assets/6629da07-f79d-4fd8-8b8c-274aa938726e" /> or kust replace de auto assinged groups witg user groups a have automatl be devices be put on users it are jsut osme ideas de tool work great like it is but i do have to do some work arounds to get it working for hour needs it works but it be a very nice to have you can see your self how intresting this idea is sins than it create differnt levels user level access group level access
Sign in to join this conversation.
No Label feature-request
1 Participants
Notifications
Due Date
No due date set.
Dependencies

No dependencies set.

Reference: DYNR/netbird#11750