# Could not impliment check execute only privileges

**URL:** <https://discourse.sensu.io/t/could-not-impliment-check-execute-only-privileges/2450>\
**Category:** Getting Started\
**Created:** [February 17, 2021, 11:17am UTC](https://discourse.sensu.io/t/could-not-impliment-check-execute-only-privileges/2450 "2021-02-17T11:17:04Z")\
**Posts on this page:** 2\
**Page:** 1

<div class="post-metadata">

**Author:** ![nadeem](https://avatars.discourse-cdn.com/v4/letter/n/8491ac/32.png) [@nadeem](https://discourse.sensu.io/u/nadeem)\
**Post date:** [February 17, 2021, 11:17am UTC](https://discourse.sensu.io/t/could-not-impliment-check-execute-only-privileges/2450/1 "2021-02-17T11:17:04Z")

</div>

I am trying to limit the privileges of a user so that it can only execute a check, no delete or create.  
With checks resource i can bind verbs “get”, “list”, “create”, “update”, “delete”. But with get and list user can’t execute the check. I had to assign “\*” verbs to get things working. Now this user can delete, create and update the checks.  
Can any body tell me if I am missing something, or this feature is not available in SensuGO’s RBAC.

---

<div class="post-metadata">

**Author:** ![jspaleta](https://sea2.discourse-cdn.com/flex016/user_avatar/discourse.sensu.io/jspaleta/32/141_2.png) [@jspaleta](https://discourse.sensu.io/u/jspaleta)\
**Post date:** [February 17, 2021, 1:10pm UTC](https://discourse.sensu.io/t/could-not-impliment-check-execute-only-privileges/2450/2 "2021-02-17T13:10:52Z")

</div>

Hey,  
It looks like check execute hasn’t been mapped to its own verb yet. It’s a bit of a special case, as checks are the only resource that can be executed in an adhoc manner. Here’s the issue on file for reference:

> <https://github.com/sensu/sensu-go/issues/3458>
>
> Goal create Role with a rules that give narrow access to execute a specifc unpublished check.
> Currently with existing RBAC I have...
