# Kibana read-only mode - more control of menu items

**URL:** https://forum.search-guard.com/t/kibana-read-only-mode-more-control-of-menu-items/1152
**Category:** Search Guard
**Created:** [October 12, 2018, 9:39am UTC](https://forum.search-guard.com/t/kibana-read-only-mode-more-control-of-menu-items/1152 "2018-10-12T09:39:26Z")
**Posts on this page:** 2
**Page:** 1

<div class="post-metadata">

### Author: ![jbeckett](https://avatars.discourse-cdn.com/v4/letter/j/e56c9b/32.png) [@jbeckett](https://forum.search-guard.com/u/jbeckett)
#### Post date: [October 12, 2018, 9:39am UTC](https://forum.search-guard.com/t/kibana-read-only-mode-more-control-of-menu-items/1152/1 "2018-10-12T09:39:26Z")

</div>

- ES 6.4.0 SG 23.1

- JRE 1.8.0 on CentOS 7.4

Enabling [Kibana read-only mode](https://docs.search-guard.com/latest/kibana-read-only) for some roles is very desirable for some groups of our users - but we’d also like them to be able to use the Discover tab to investigate the data (they don’t need to save searches, so they’d still be read-only users). There are some cases where we’d like to enable other menu items too (Monitor?)

I thought I remembered seeing a way to do this already - did I imagine that, or was it perhaps an X-Pack thing?

If not, can I request it as a feature? Not sure how it would be configured - you might want different item availability for different roles, so this might not be sufficient in general (but might be for a first version):

searchguard.readonly\_mode.roles: [“sg\_read\_only\_1”, “sg\_read\_only\_2”, …]

searchguard.readonly\_mode.menus: [“discover”, “visualize”, “dashboards”, “monitor”] # logout, collapse always present

---

<div class="post-metadata">

### Author: ![jkressin](https://sea1.discourse-cdn.com/flex019/user_avatar/forum.search-guard.com/jkressin/32/9_2.png) [@jkressin](https://forum.search-guard.com/u/jkressin)
#### Post date: [October 15, 2018, 1:49pm UTC](https://forum.search-guard.com/t/kibana-read-only-mode-more-control-of-menu-items/1152/2 "2018-10-15T13:49:14Z")

</div>

Hi,

I am not aware that X-Pack has this feature (yet). However, we are actively working on improving Kibana access control, so the feature is coming. We don’t have a ETA yet.

> **···**
>
> On Friday, October 12, 2018 at 11:39:26 AM UTC+2, [jbeckett@ft-services.com](mailto:jbeckett@ft-services.com) wrote:
> 
> > - ES 6.4.0 SG 23.1
> 
> > - JRE 1.8.0 on CentOS 7.4
> 
> > 
> 
> > Enabling [Kibana read-only mode](https://docs.search-guard.com/latest/kibana-read-only) for some roles is very desirable for some groups of our users - but we’d also like them to be able to use the Discover tab to investigate the data (they don’t need to save searches, so they’d still be read-only users). There are some cases where we’d like to enable other menu items too (Monitor?)
> 
> > 
> 
> > I thought I remembered seeing a way to do this already - did I imagine that, or was it perhaps an X-Pack thing?
> 
> > 
> 
> > If not, can I request it as a feature? Not sure how it would be configured - you might want different item availability for different roles, so this might not be sufficient in general (but might be for a first version):
> 
> > 
> 
> > searchguard.readonly\_mode.roles: [“sg\_read\_only\_1”, “sg\_read\_only\_2”, …]
> 
> > searchguard.readonly\_mode.menus: [“discover”, “visualize”, “dashboards”, “monitor”] # logout, collapse always present
> 
> > 
> 
> >
