# Default RBAC Behavior

By default, any newly created user **without an assigned role** has access to **all PostgreSQL instances** monitored by the platform.

This default behavior can be changed at the platform level.&#x20;

When enabled, this setting ensures that newly created users have no access to any instances until one or more roles are explicitly assigned.

{% hint style="info" %}
This configuration is particularly useful when using **automatic user provisioning**, such as users created through LDAP integration, where access control is expected to be enforced strictly through roles.
{% endhint %}

<figure><img src="https://1072624949-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FlcWi6G1jtNuyGT9C0pkc%2Fuploads%2F2Gxleh9wTfnAEhdDXRXi%2FrbacSettings.png?alt=media&#x26;token=2b5d2b6b-7e6f-42db-81cf-ecc39244bec4" alt=""><figcaption></figcaption></figure>
