# User does not have write permissions for the index

**URL:** <https://community.stardog.com/t/user-does-not-have-write-permissions-for-the-index/4369>\
**Category:** Support\
**Created:** [May 5, 2023, 3:19am UTC](https://community.stardog.com/t/user-does-not-have-write-permissions-for-the-index/4369 "2023-05-05T03:19:39Z")\
**Posts on this page:** 2\
**Page:** 1

<div class="post-metadata">

**Author:** ![Cesar](https://avatars.discourse-cdn.com/v4/letter/c/e47774/32.png) [@Cesar](https://community.stardog.com/u/Cesar)\
**Post date:** [May 5, 2023, 3:19am UTC](https://community.stardog.com/t/user-does-not-have-write-permissions-for-the-index/4369/1 "2023-05-05T03:19:39Z")

</div>

Hi,

# Problem

We're playing with the roles and permission. We have a database with three graphs, namely, `graph1, graph2, graph3`, we want to create a user with read permission over all the three graphs, as well as write permission to `graph1` and `graph2`.

```auto
| action | resource_type | resource | remove |
|---------|-----------------|-----------|----------|
| READ | * | myDB | x | 
| WRITE |named-graph | graph1 | x | 
| WRITE |named-graph | graph2 | x | 
| READ |named-graph | graph3 | x | 
| ALL |metadata | myDB | x | 

```

We tried the above setting using the Studio, but when we try to write in a graph like `graph1`, we get the following error

```auto
User does not have write permissions for the index. User identification "username"; index name "myDB"

```

# Question

How we can achieve it through actions and permissions to create a user with read permission over all the three graphs, as well as write permission to `graph1` and `graph2` but not write permission for `graph1`?

Thank you

---

<div class="post-metadata">

**Author:** ![stephen](https://yyz2.discourse-cdn.com/flex030/user_avatar/community.stardog.com/stephen/32/27_2.png) [@stephen](https://community.stardog.com/u/stephen)\
**Post date:** [May 5, 2023, 12:50pm UTC](https://community.stardog.com/t/user-does-not-have-write-permissions-for-the-index/4369/2 "2023-05-05T12:50:17Z")

</div>

Hi,

A) You would need to ensure that `security.named.graphs` is set to `true` for myDB.  
B) Your user does not have WRITE permission for myDB  
C) `named-graph` resources need a database name specified, e.g., [WRITE, named-graph:myDB\graph1]  
D) Currently you need to specify READ/WRITE access for every named graph explicitly. You could probably get away with granting the user [ALL, named-graph:myDB\graph1], [ALL, named-graph:myDB\graph2], and then [READ, named-graph:myDB\graph3], though I suppose in production that could have unintended consequences if your user has malicious intent
