<a id="user"></a>

# User

See also: [How to manage users](https://documentation.ubuntu.com/juju/4.0/howto/manage-users.md#manage-users)

In Juju, a **user** is any person able to log in to a Juju [controller](https://documentation.ubuntu.com/juju/4.0/reference/controller.md#controller).

#### NOTE
Juju users are not related in any way to the client system users.

Users can be created in two ways: Implicitly by bootstrapping a controller into a cloud or explicitly by adding a user to a controller (`juju add-user`).

A user logs in to a Juju controller using a username and a password. The user created implicitly gets the username `admin` and  is prompted to create a password the first time they attempt to log out. A user created explicitly gets the username assigned to them when being added (via `juju add-user`) and is prompted to create login details when they register the new controller with their Juju client.

#### NOTE
A user’s username and password are entirely different from the credentials referenced in `juju` commands such as `add-credential`—those are about access to a cloud, whereas these are about access to a Juju controller.

#### IMPORTANT
Multiple users can be accommodated by the same Juju client. However, there can only be one user logged in at a time.

Every user is associated with an access level. The default level for the user created implicitly (`admin`) is the controller `superuser` access level, which means they can do everything at the level of the entire controller. The default level for a user created explicitly is the controller `login` level, which means they can do nothing on the controller other than register it with their client and log in to it – for anything more they must be granted a higher level explicitly.

<a id="user-access-levels"></a>

## User access levels

A Juju user may have different abilities, according to the access level they have been granted. This document describes the various access levels and the corresponding abilities.

### Valid access levels for controllers

<a id="user-access-controller-login"></a>

#### `login`

Granted: Via \`juju register.

Abilities: Log in to the controller.

<a id="user-access-controller-superuser"></a>

#### `superuser`

Granted: Automatically by bootstrapping a controller or by having the username ‘admin’.

Abilities: Do anything that it is possible to do at the level of a controller.

#### NOTE
A person logged into the `jaas` controller automatically has the login access level. This is automatically granted via ` juju grant login everyone@external`.

#### NOTE
Since multiple controllers—and therefore multiple controller administrators—are possible, there is no such thing as an overarching “Juju administrator”. Nevertheless, a user with the superuser access level is usually what people refer to as “the admin”.

### Valid access levels for clouds

A controller can manage models on many clouds. With cloud-level access you can give a user permission to access one cloud but not another related to that controller.

<a id="user-access-cloud-add-model"></a>

#### `add-model`

Granted: Via [juju grant-cloud](https://documentation.ubuntu.com/juju/4.0/reference/juju-cli/list-of-juju-cli-commands/grant-cloud.md#command-juju-grant-cloud).

Abilities: Add a model. Grant another user model-level permissions.

<a id="user-access-cloud-admin"></a>

#### `admin`

Granted: Via [juju grant-cloud](https://documentation.ubuntu.com/juju/4.0/reference/juju-cli/list-of-juju-cli-commands/grant-cloud.md#command-juju-grant-cloud).

Abilities: You can do anything that it is possible to do at the level of a cloud.

### Valid access levels for models

<a id="user-access-model-read"></a>

#### `read`

Granted: Via [juju grant](https://documentation.ubuntu.com/juju/4.0/reference/juju-cli/list-of-juju-cli-commands/grant.md#command-juju-grant).

Abilities: View the content of a model without changing it. Use any of the read commands.

<a id="user-access-model-write"></a>

#### `write`

Granted: Via [juju grant](https://documentation.ubuntu.com/juju/4.0/reference/juju-cli/list-of-juju-cli-commands/grant.md#command-juju-grant).

Abilities: Deploy and manage applications on the model.

<a id="user-access-model-admin"></a>

#### `admin`

Granted: Via [juju grant](https://documentation.ubuntu.com/juju/4.0/reference/juju-cli/list-of-juju-cli-commands/grant.md#command-juju-grant).

Abilities: Do anything that it is possible to do at the level of a model.

### Valid access levels for application offers

<a id="user-access-offer-read"></a>

#### `read`

Granted: Via [juju grant](https://documentation.ubuntu.com/juju/4.0/reference/juju-cli/list-of-juju-cli-commands/grant.md#command-juju-grant).

Abilities: View offers during a search with [juju find-offers](https://documentation.ubuntu.com/juju/4.0/reference/juju-cli/list-of-juju-cli-commands/find-offers.md#command-juju-find-offers).

<a id="user-access-offer-consume"></a>

#### `consume`

Granted: Via [juju grant](https://documentation.ubuntu.com/juju/4.0/reference/juju-cli/list-of-juju-cli-commands/grant.md#command-juju-grant).

Abilities: Relate an application to the offer.

<a id="user-access-offer-admin"></a>

#### `admin`

Granted: Via [juju grant](https://documentation.ubuntu.com/juju/4.0/reference/juju-cli/list-of-juju-cli-commands/grant.md#command-juju-grant).

Abilities: You can do anything that it is possible to do at the level of an offer.
