# How can I create a user with no posting privileges

**URL:** <https://meta.discourse.org/t/how-can-i-create-a-user-with-no-posting-privileges/32894>\
**Category:** Feature\
**Created:** [2015年九月3日 23:30 UTC](https://meta.discourse.org/t/how-can-i-create-a-user-with-no-posting-privileges/32894 "2015-09-03T23:30:55Z")\
**Posts on this page:** 13\
**Page:** 1

<div class="post-metadata">

**Author:** ![OnceWas](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/oncewas/32/40734_2.png) [@OnceWas](https://meta.discourse.org/u/OnceWas)\
**Post date:** [2015年九月3日 23:30 UTC](https://meta.discourse.org/t/how-can-i-create-a-user-with-no-posting-privileges/32894/1 "2015-09-03T23:30:55Z")

</div>

I know this seems like an odd request - but bear with me. I would like to create a user that can’t create posts. I want to be able to create a Discourse profile for an organization, separate from the person responsible for that organization.

An example would be YoyoDyne Inc., as a separate entity from the YoyoDyne CEO. I would like the CEO to be able to create topics and posts, but I would not want YoyoDyne Inc. to be able to post. The CEO would want to link to their company profile when they wanted to highlight the company, instead of linking to their own profile and posting history.

---

<div class="post-metadata">

**Author:** ![cpradio](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/cpradio/32/4970_2.png) [@cpradio](https://meta.discourse.org/u/cpradio)\
**Post date:** [2015年九月3日 23:43 UTC](https://meta.discourse.org/t/how-can-i-create-a-user-with-no-posting-privileges/32894/2 "2015-09-03T23:43:00Z")

</div>

Just deactivate the account after it is created? (maybe)…

---

<div class="post-metadata">

**Author:** ![OnceWas](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/oncewas/32/40734_2.png) [@OnceWas](https://meta.discourse.org/u/OnceWas)\
**Post date:** [2015年九月3日 23:43 UTC](https://meta.discourse.org/t/how-can-i-create-a-user-with-no-posting-privileges/32894/3 "2015-09-03T23:43:56Z")

</div>

Interesting. Would that allow the CEO to modify that account’s profile after deactivation?

---

<div class="post-metadata">

**Author:** ![cpradio](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/cpradio/32/4970_2.png) [@cpradio](https://meta.discourse.org/u/cpradio)\
**Post date:** [2015年九月3日 23:45 UTC](https://meta.discourse.org/t/how-can-i-create-a-user-with-no-posting-privileges/32894/4 "2015-09-03T23:45:35Z")

</div>

Is the CEO a staff member or admin? Then yes.

---

<div class="post-metadata">

**Author:** ![OnceWas](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/oncewas/32/40734_2.png) [@OnceWas](https://meta.discourse.org/u/OnceWas)\
**Post date:** [2015年九月4日 04:25 UTC](https://meta.discourse.org/t/how-can-i-create-a-user-with-no-posting-privileges/32894/7 "2015-09-04T04:25:17Z")

</div>

Not sure I want to give the CEO that role. This would not be our own CEO. 🙂

---

<div class="post-metadata">

**Author:** ![riking](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/riking/32/170938_2.png) [@riking](https://meta.discourse.org/u/riking)\
**Post date:** [2015年九月4日 05:29 UTC](https://meta.discourse.org/t/how-can-i-create-a-user-with-no-posting-privileges/32894/8 "2015-09-04T05:29:06Z")

</div>

Is there any reason you need a technical restriction in addition to a policy restriction here?

---

<div class="post-metadata">

**Author:** ![OnceWas](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/oncewas/32/40734_2.png) [@OnceWas](https://meta.discourse.org/u/OnceWas)\
**Post date:** [2015年九月4日 05:30 UTC](https://meta.discourse.org/t/how-can-i-create-a-user-with-no-posting-privileges/32894/9 "2015-09-04T05:30:18Z")

</div>

Not sure I understand the difference between technical and policy.

---

<div class="post-metadata">

**Author:** ![riking](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/riking/32/170938_2.png) [@riking](https://meta.discourse.org/u/riking)\
**Post date:** [2015年九月4日 05:32 UTC](https://meta.discourse.org/t/how-can-i-create-a-user-with-no-posting-privileges/32894/10 "2015-09-04T05:32:45Z")

</div>

Technical restriction = the software prevents you from doing it  
Policy restriction = “don’t do this” (and reprimands will be taken if you do)

---

<div class="post-metadata">

**Author:** ![OnceWas](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/oncewas/32/40734_2.png) [@OnceWas](https://meta.discourse.org/u/OnceWas)\
**Post date:** [2015年九月4日 05:35 UTC](https://meta.discourse.org/t/how-can-i-create-a-user-with-no-posting-privileges/32894/11 "2015-09-04T05:35:52Z")

</div>

Got it, thanks for clearing that up. I can see the CEO forgetting that they are logged in as the corporate role when they updated the company profile, and then posting all over the place before they realize that they haven’t been posting as themselves…

I’d be open to developing a plugin that prevents members of a specific group from posting, unless there’s an easier way to do this.

---

<div class="post-metadata">

**Author:** ![cpradio](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/cpradio/32/4970_2.png) [@cpradio](https://meta.discourse.org/u/cpradio)\
**Post date:** [2015年九月4日 12:36 UTC](https://meta.discourse.org/t/how-can-i-create-a-user-with-no-posting-privileges/32894/12 "2015-09-04T12:36:11Z")

</div>

> [@OnceWas](#):
>
> Got it, thanks for clearing that up. I can see the CEO forgetting that they are logged in as the corporate role when they updated the company profile, and then posting all over the place before they realize that they haven’t been posting as themselves…

So if you deactivate the account, make the policy: Any changes to that account’s profile must be submitted to X (who has Staff/Admin rights). That person then makes the necessary changes.

---

<div class="post-metadata">

**Author:** ![codinghorror](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/codinghorror/32/110067_2.png) [@codinghorror](https://meta.discourse.org/u/codinghorror)\
**Post date:** [2015年九月4日 18:27 UTC](https://meta.discourse.org/t/how-can-i-create-a-user-with-no-posting-privileges/32894/13 "2015-09-04T18:27:51Z")

</div>

You are kind of imagineering a problem here, though. You’re _imagining_ it will be a problem without any proof that it is. This is a dangerous way to design software in my experience.

---

<div class="post-metadata">

**Author:** ![OnceWas](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/oncewas/32/40734_2.png) [@OnceWas](https://meta.discourse.org/u/OnceWas)\
**Post date:** [2015年九月8日 23:15 UTC](https://meta.discourse.org/t/how-can-i-create-a-user-with-no-posting-privileges/32894/14 "2015-09-08T23:15:52Z")

</div>

I agree that we’re a bit of an edge case, feature-wise, but we’re definitely mainstream, behavior-wise.

I would love to know that our users would understand - and always remember - that they are logged in with one account vs another. But absent-mindedness is deeply ingrained. Typing into the wrong chat window, texting the wrong person, replying to all, or forgetting which account you’re logged into, are fairly common occurrences.

Policies are great, but they don’t fix human behavior.

I am currently looking at creating a custom trust level group, or equivalent functionality, which would not allow posting. A more open-ended approach would be to create a trust level group with admin-definable or admin-settable custom privileges.

---

<div class="post-metadata">

**Author:** ![Ahmed\_Gagan](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/ahmed_gagan/32/161985_2.png) [@Ahmed\_Gagan](https://meta.discourse.org/u/Ahmed_Gagan)\
**Post date:** [2020年四月9日 08:41 UTC](https://meta.discourse.org/t/how-can-i-create-a-user-with-no-posting-privileges/32894/15 "2020-04-09T08:41:47Z")

</div>

您可以使用我们的插件撤销某些信任等级用户在主题中发帖的权限。  
您可以指定在主题中发帖所需的最低信任等级，即可实现该功能。  
链接如下：[自定义信任等级](https://meta.discourse.org/t/custom-trust-level/147253)
