# The default user neo4j doesn't have admin role

**URL:** <https://community.neo4j.com/t/the-default-user-neo4j-doesnt-have-admin-role/74673>\
**Category:** Operations\
**Tags:** cypher, operations\
**Created:** [July 14, 2025, 4:07am UTC](https://community.neo4j.com/t/the-default-user-neo4j-doesnt-have-admin-role/74673 "2025-07-14T04:07:52Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![syolbe1](https://sea1.discourse-cdn.com/flex021/user_avatar/community.neo4j.com/syolbe1/32/32796_2.png) [@syolbe1](https://community.neo4j.com/u/syolbe1)\
**Post date:** [July 14, 2025, 4:07am UTC](https://community.neo4j.com/t/the-default-user-neo4j-doesnt-have-admin-role/74673/1 "2025-07-14T04:07:52Z")

</div>

The default user, one (admin) that I created, won't have admin role.

 ![image](https://us1.discourse-cdn.com/flex021/uploads/neo4jcommunity/original/3X/a/4/a4f494ef323807c2c4748970914bd6ae42bd65cb.png)

What can be wrong ?

It seems to be a basic question, but couldn't find any answer in the doc.

I need admin to run dynamically created cypher commands.  
For example:

```auto
// Create GlobalSearchFT index
CALL db.schema.nodeTypeProperties() YIELD nodeType, propertyName
WITH DISTINCT split(nodeType, ':')[1] AS label
WHERE label IS NOT NULL
WITH collect(label) AS labels

// Step 2: Generate and execute the index command
CALL apoc.cypher.run(
  'CREATE FULLTEXT INDEX GlobalSearchFT IF NOT EXISTS ' +
  'FOR (n:' + apoc.text.join(labels, '|') + ') ' +
  'ON EACH [n.searchText]' +
  'OPTIONS { indexConfig: { `fulltext.analyzer`: "standard" } }',
  {}
)
YIELD value
RETURN value;

```

and the error message:

```auto
Neo.ClientError.Security.Forbidden
Schema operation 'create_index' on database 'neo4j' is not allowed for user 'neo4j' with FULL overridden by READ.

```

---

<div class="post-metadata">

**Author:** ![therese.magnusson](https://sea1.discourse-cdn.com/flex021/user_avatar/community.neo4j.com/therese.magnusson/32/32815_2.png) [@therese.magnusson](https://community.neo4j.com/u/therese.magnusson)\
**Post date:** [July 14, 2025, 6:45am UTC](https://community.neo4j.com/t/the-default-user-neo4j-doesnt-have-admin-role/74673/2 "2025-07-14T06:45:15Z")

</div>

Hi, are you on Community?

Roles and privilege management are only available in the Enterprise edition and Aura (with different tiers allowing different levels of granularity).

For the Community edition, all users are basically an admin and the roles column in SHOW USERS are set to `null` to indicate that there isn't really any separate roles available in Community.

Have you tried running your query and had it fail on lack of privileges? If so I'd think that might be an issue but the lack of reported roles (if on Community) isn't as such.

Hope that helped,  
Therese

---

<div class="post-metadata">

**Author:** ![therese.magnusson](https://sea1.discourse-cdn.com/flex021/user_avatar/community.neo4j.com/therese.magnusson/32/32815_2.png) [@therese.magnusson](https://community.neo4j.com/u/therese.magnusson)\
**Post date:** [July 14, 2025, 6:48am UTC](https://community.neo4j.com/t/the-default-user-neo4j-doesnt-have-admin-role/74673/3 "2025-07-14T06:48:32Z")

</div>

To add on to this with what we have in the documentation, [https://neo4j.com/docs/operations-manual/current/authentication-authorization/manage-users/#access-control-list-users](https://neo4j.com/docs/operations-manual/current/authentication-authorization/manage-users/#access-control-list-users)

Both the roles, suspended and home columns have

> It returns `null` in Community edition.

in their descriptions and are marked as not available/useful in the community column.  
They are just returned with `null` to always have the same column set, regardless of edition.

 ![image](https://us1.discourse-cdn.com/flex021/uploads/neo4jcommunity/original/3X/8/8/8898e93b91f572f0a5924f2247f76674ad2ec972.png)

---

<div class="post-metadata">

**Author:** ![syolbe1](https://sea1.discourse-cdn.com/flex021/user_avatar/community.neo4j.com/syolbe1/32/32796_2.png) [@syolbe1](https://community.neo4j.com/u/syolbe1)\
**Post date:** [July 15, 2025, 3:30am UTC](https://community.neo4j.com/t/the-default-user-neo4j-doesnt-have-admin-role/74673/4 "2025-07-15T03:30:23Z")

</div>

Hi Therese,  
Thanks for your reply.  
Yes indeed, I am using the Community version. As you mentioned, user neo4j should have admin, so it may be a bug ?

---

<div class="post-metadata">

**Author:** ![therese.magnusson](https://sea1.discourse-cdn.com/flex021/user_avatar/community.neo4j.com/therese.magnusson/32/32815_2.png) [@therese.magnusson](https://community.neo4j.com/u/therese.magnusson)\
**Post date:** [July 15, 2025, 7:46am UTC](https://community.neo4j.com/t/the-default-user-neo4j-doesnt-have-admin-role/74673/5 "2025-07-15T07:46:52Z")

</div>

Let's look into your exception and see what it tells us then (didn't look to closely before 🙈)

```auto
Neo.ClientError.Security.Forbidden
Schema operation 'create_index' on database 'neo4j' is not allowed for user 'neo4j' with FULL overridden by READ.

```

This is one of the confusing exceptions that comes from running procedures and how the procedure mode affects things.

So the `with FULL` part indicates that you have full access and no privilege restrictions (which makes sense for Community). However, it is then overridden (`overridden by READ`) with the privilege level of the procedure mode (READ/WRITE/...) when you run a procedure.

And since the READ level of privileges don't allow writes, even less so schema writes, the query fails.

So you are trying to do schema writes in a read-only procedure, that is the cause of your problem. You would likely need a procedure with SCHEMA mode to create indexes inside of a procedure.

Now I'm not familiar enough with the apoc procedures to know if there is anything that would fit your use case, I believe there is a WRITE version of `apoc.cypher.run` (maybe named `apoc.cypher.doRun` but not sure) but I don't think it would be enough to be able to run create index but feel free to try (likely to get the same error but with `overridden by WRITE`).

_So to summarise, not a bug but expected behaviour from running a schema write command in a read-only procedure :(_

Update: Checked with my colleague that has more knowledge of apoc and she found the `apoc.cypher.runSchema` procedure ([documentation](https://neo4j.com/docs/apoc/current/overview/apoc.cypher/apoc.cypher.runSchema/)) which is probably the one you want.
