# What does READ action groups exactly?

**URL:** https://forum.search-guard.com/t/what-does-read-action-groups-exactly/1039
**Category:** Search Guard
**Created:** [July 26, 2018, 3:09am UTC](https://forum.search-guard.com/t/what-does-read-action-groups-exactly/1039 "2018-07-26T03:09:47Z")
**Posts on this page:** 2
**Page:** 1

<div class="post-metadata">

### Author: ![Tomoyuki](https://avatars.discourse-cdn.com/v4/letter/t/d9b06d/32.png) [@Tomoyuki](https://forum.search-guard.com/u/Tomoyuki)
#### Post date: [July 26, 2018, 3:09am UTC](https://forum.search-guard.com/t/what-does-read-action-groups-exactly/1039/1 "2018-07-26T03:09:47Z")

</div>

READ action group is described as ‘Grants read permissions like get, mget or getting field mappings, but exludes search permissions’ in the page [Using and defining action groups](https://docs.search-guard.com/latest/action-groups).

(BTW, there’s typo in the sentence: exludes → excludes)

However, from my testing, a user who has READ is able to search documents.

Is this an expected behavior?

READ action group contains indices:data/read\* permission.

Is that understanding correct?

Versions

Elasticserch version: 6.3.1

SeachGuard ES plugin version: 6-6.3.1-22.3

Kibana version: 6.3.1

SearchGuard Kibana plugin version: 6.3.1-14-beta-1

> **···**
>
> From my understanding, indices:data/read\* includes indices/data/read/search\*.

---

<div class="post-metadata">

### Author: ![jkressin](https://sea1.discourse-cdn.com/flex019/user_avatar/forum.search-guard.com/jkressin/32/9_2.png) [@jkressin](https://forum.search-guard.com/u/jkressin)
#### Post date: [July 26, 2018, 6:17pm UTC](https://forum.search-guard.com/t/what-does-read-action-groups-exactly/1039/2 "2018-07-26T18:17:23Z")

</div>

Yes, this is an error in the documentation. Thanks for pointing it out, we will correct it asap. Your understanding is correct here.

> **···**
>
> On Thursday, July 26, 2018 at 5:09:47 AM UTC+2, Tomoyuki Saito wrote:
> 
> > READ action group is described as ‘Grants read permissions like get, mget or getting field mappings, but exludes search permissions’ in the page [Using and defining action groups](https://docs.search-guard.com/latest/action-groups).
> 
> > (BTW, there’s typo in the sentence: exludes → excludes)
> 
> > 
> 
> > However, from my testing, a user who has READ is able to search documents.
> 
> > Is this an expected behavior?
> 
> > 
> 
> > READ action group contains indices:data/read\* permission.
> 
> > From my understanding, indices:data/read\* includes indices/data/read/search\*.
> 
> > Is that understanding correct?
> 
> > 
> 
> > 
> 
> > Versions
> 
> > 
> 
> > Elasticserch version: 6.3.1
> 
> > SeachGuard ES plugin version: 6-6.3.1-22.3
> 
> > Kibana version: 6.3.1
> 
> > SearchGuard Kibana plugin version: 6.3.1-14-beta-1
