should be rw for the user only
should be rw for the user only