# rpk security role assign

> For the complete documentation index, see [llms.txt](https://docs.redpanda.com/llms.txt). Component-specific: [streaming-full.txt](https://docs.redpanda.com/streaming-full.txt)

---
title: rpk security role assign
latest-redpanda-tag: v26.2.1
latest-console-tag: v3.10.0
latest-operator-version: v26.2.1
# EOL = End-of-Life (support lifecycle status)
page-is-nearing-eol: "false"
page-is-past-eol: "false"
page-eol-date: July 28, 2027
latest-connect-version: 4.104.0
docname: rpk/rpk-security/rpk-security-role-assign
page-component-name: streaming
page-version: "26.2"
page-component-version: "26.2"
page-component-title: Streaming
page-relative-src-path: rpk/rpk-security/rpk-security-role-assign.adoc
page-edit-url: https://github.com/redpanda-data/docs/edit/main/modules/reference/pages/rpk/rpk-security/rpk-security-role-assign.adoc
description: Assign a Redpanda role to a principal. The <code>--principal</code> flag accepts principals with the format '<PrincipalPrefix>:<Principal>'.
page-git-created-date: "2024-04-30"
page-git-modified-date: "2026-08-01"
support-status: supported
---

<!-- Source: https://docs.redpanda.com/streaming/current/reference/rpk/rpk-security/rpk-security-role-assign.md -->

Assign a Redpanda role to a principal.

The `--principal` flag accepts principals with the format '<PrincipalPrefix>:<Principal>'. If 'PrincipalPrefix' is not provided, then defaults to 'User:'.

## [](#usage)Usage

```bash
rpk security role assign <role> --principal <principals...> [flags]
```

## [](#aliases)Aliases

```bash
rpk security role add
```

## [](#examples)Examples

This section provides examples of how to use `rpk security role assign`.

Assign role `redpanda-admin` to user `red`.

```bash
rpk security role assign redpanda-admin --principal red
```

Assign role `redpanda-admin` to users `red` and `panda`.

```bash
rpk security role assign redpanda-admin --principal red,panda
```

Assign role `topic-reader` to group `analytics`.

```bash
rpk security role assign topic-reader --principal Group:analytics
```

Assign role `ops-admin` to both a user and a group.

```bash
rpk security role assign ops-admin --principal alice,Group:sre
```

## [](#flags)Flags

| Value | Type | Description |
| --- | --- | --- |
| --principal | stringSlice | Principal to assign the role to (repeatable). |

## [](#global-flags)Global flags

| Value | Type | Description |
| --- | --- | --- |
| --config | string | Redpanda or rpk config file; default search paths are ~/.config/rpk/rpk.yaml, $PWD/redpanda.yaml, and /etc/redpanda/redpanda.yaml. |
| -X, --config-opt | stringArray | Override rpk configuration settings; -X help for detail or -X list for terser detail. |
| --ignore-profile | bool | Ignore rpk.yaml and redpanda.yaml; use default settings. |
| --profile | string | rpk profile to use. |
| -v, --verbose | bool | Enable verbose logging. |