ES ships with several built-in roles that control dashboard access and functionality:
**ess_admin** — Full administrative access: manage correlation searches, configure settings, and modify navigation. **ess_analyst** — Investigate, triage notable events, and run adaptive response actions. **ess_user** — Read-only view of dashboards and notable events.
Custom roles can be created inheriting from these base ES roles. Navigation items can be hidden per-role, limiting what each team sees.