---
title: "PostgreSQL PGVector user management"
sidebar_label: "User management"
sidebar_position: 8
description: "How to create a user, change their password, configure access to a PostgreSQL PGVector database, and work with privileges"
---

import Formbricks from '@theme/MDXComponents/Formbricks'
import MoreVerticalIcon from '@selectel/docux/icons/more-vertical'

# PostgreSQL PGVector user management

Users are created to access databases in a PostgreSQL PGVector cluster.

To create a database in a cluster, you must first [create a user](#create-user).

Only the cluster itself is available to users for work — there is no access to cluster nodes since they are hosted on the Selectel side. By default, all users in the cluster have the same permissions.

Access to a single PostgreSQL PGVector database can be granted to multiple users, but there can be only one [database owner](#database-owner). Users can be [granted privileges on database objects](#grant-privileges).

## Database owner \{#database-owner}

When creating a PostgreSQL PGVector database, you must select an owner user.

A PostgreSQL PGVector database owner is a user who inherits ownership of objects from deleted users. After a user is deleted, you will not lose access to the objects they created, but will be able to manage them via the owner. Unlike a regular user, the database owner has access to all its objects and can perform operations on them.

## Create a user \{#create-user}

1. In the [Control panel](https://my.selectel.ru/vpc/default/dbaas/), in the top menu, click **Products** and select **Cloud Databases**.
2. Open the tab **Active**.
3. Open the database cluster page → tab **Users**.
4. Click **Create user**.
5. Enter a name and password. Save the password — it will not be stored in the control panel.
6. Click **Save**.

## Change user password \{#change-user-password}

After creating a cluster, the user password can be changed. Remember to change the password in your application.

1. In the [Control panel](https://my.selectel.ru/vpc/default/dbaas/), in the top menu, click **Products** and select **Cloud Databases**.
2. Open the tab **Active**.
3. Open the cluster page → tab **Users**.
4. In the user's <MoreVerticalIcon /> menu, select **Change password**.
5. Enter or generate a new password and save the changes.

## Configure database access \{#configure-access-to-database}

### Grant access to a user \{#grant-user-access}

Multiple users can be granted access to a single PostgreSQL PGVector database.

1. In the [Control panel](https://my.selectel.ru/vpc/default/dbaas/), in the top menu, click **Products** and select **Cloud Databases**.
2. Open the tab **Active**.
3. Open the database cluster page → **Databases** tab → database page.
4. In the **Have access** block, click **Add** and select a user.

The user can only connect to the database (`CONNECT`) and cannot perform operations on objects. To grant the user access to objects, [grant them the required privileges](#grant-privileges).

### Change database owner \{#change-database-owner}

A PostgreSQL PGVector database owner is assigned upon its creation. The owner cannot be deleted (each database must have an owner), but can be changed to another one.

1. In the [Control panel](https://my.selectel.ru/vpc/default/dbaas/), in the top menu, click **Products** and select **Cloud Databases**.
2. Open the tab **Active**.
3. Open the database cluster page → **Databases** tab → database page.
4. In the **Database owner** list, select another owner.

### Remove access for a user \{#revoke-access-for-user}

1. In the [Control panel](https://my.selectel.ru/vpc/default/dbaas/), in the top menu, click **Products** and select **Cloud Databases**.
2. Open the tab **Active**.
3. Open the database cluster page → **Databases** tab → database page.
4. In the **Have access** block, remove the user.

## Configure user privileges \{#configure-user-privileges}

By default, a user has no access to operations on any database objects (schemas, tables, functions) unless they are the owner of that database. You can grant users a privilege (access right) on an object.

By default, object owners have access and all rights to the object.

### Grant privileges \{#grant-privileges}

You can grant privileges on database objects to users using the [GRANT](https://www.postgresql.org/docs/current/sql-grant.html) command. Privileges can be as follows: `SELECT`, `INSERT`, `DELETE`, `USAGE`.

An example of granting read access (`SELECT`) to the table `table` to the user `user`:

```bash
GRANT SELECT ON table TO user;
```

### Create a schema user with read-only permissions \{#create-read-only-user}

You can create a user with access to the cluster database, to a table in the default schema, and to all tables in the schema.

All new tables will be automatically created with read-only access for this user.

1. [Create a user](#create-user).

2. [Connect to the database](/managed-databases/pgvector/connect-to-cluster.mdx).

3. Create the schema `schema` and table `table`:

   ```bash
   CREATE SCHEMA schema;
   CREATE TABLE schema.table(i int);
   INSERT INTO schema.table(i) values(1);
   ```

4. Grant privileges to the user `user`:

   ```bash
   GRANT USAGE ON SCHEMA schema TO user;
   GRANT SELECT ON ALL TABLES IN SCHEMA schema TO user;
   ALTER DEFAULT PRIVILEGES IN SCHEMA schema GRANT SELECT ON TABLES TO user;
   ```

### Revoke privileges \{#revoke-privileges}

You can revoke privileges from a user using the command [REVOKE](https://www.postgresql.org/docs/current/sql-revoke.html).

An example of revoking a privilege from the user `user` on the schema `schema`:

```bash
REVOKE USAGE ON SCHEMA schema FROM user;
```

<Formbricks />
