# Not enough permissions for saving visualizations

**URL:** <https://forum.search-guard.com/t/not-enough-permissions-for-saving-visualizations/2002>\
**Category:** Search Guard\
**Created:** [November 10, 2020, 10:27am UTC](https://forum.search-guard.com/t/not-enough-permissions-for-saving-visualizations/2002 "2020-11-10T10:27:22Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![Kosmonafft](https://sea1.discourse-cdn.com/flex019/user_avatar/forum.search-guard.com/kosmonafft/32/1010_2.png) [@Kosmonafft](https://forum.search-guard.com/u/Kosmonafft)\
**Post date:** [November 10, 2020, 10:27am UTC](https://forum.search-guard.com/t/not-enough-permissions-for-saving-visualizations/2002/1 "2020-11-10T10:27:23Z")

</div>

Hi,

my question is related to this post: [Grant Users Permission to Save Visualizations](https://forum.search-guard.com/t/grant-users-permission-to-save-visualizations/1535)

What are the exact permission settings to enable my users to save their visualizations?

My Role is:

```
{
  "description": "test_role",
  "cluster_permissions": [
    "SGS_CLUSTER_ALL",
    "SGS_CLUSTER_COMPOSITE_OPS",
    "SGS_CLUSTER_COMPOSITE_OPS_RO",
    "SGS_CLUSTER_MONITOR",
    "cluster:monitor/main\""
  ],
  "index_permissions": [
    {
      "index_patterns": [
        "index-**"
      ],
      "fls": [],
      "masked_fields": [],
      "allowed_actions": [
        "SGS_INDICES_ALL",
        "SGS_INDICES_MONITOR",
        "SGS_READ",
        "SGS_SEARCH",
        "SGS_UNLIMITED",
        "SGS_WRITE",
        "indices:data/write/index"
      ]
    }
  ],
  "tenant_permissions": [
    {
      "allowed_actions": [
        "SGS_SIGNALS_ALL"
      ],
      "tenant_patterns": [
        "SGS_GLOBAL_TENANT"
      ]
    }
  ]
}

```

as you see I ended up granting all permissions available, but still the user is not able to save visualization. My testuser is mapped to the role `test_role` and `SGS_KIBANA_USER`

`{ message: "no permissions for [indices:data/write/index] and User [name=testuser, backend_roles=[], requestedTenant=null]: [security_exception] no permissions for [indices:data/write/index] and User [name=testuser, backend_roles=[], requestedTenant=null]", statusCode: 403, error: "Forbidden" }`

What am I doing wrong?

Thank you

---

<div class="post-metadata">

**Author:** ![Kosmonafft](https://sea1.discourse-cdn.com/flex019/user_avatar/forum.search-guard.com/kosmonafft/32/1010_2.png) [@Kosmonafft](https://forum.search-guard.com/u/Kosmonafft)\
**Post date:** [November 10, 2020, 11:09am UTC](https://forum.search-guard.com/t/not-enough-permissions-for-saving-visualizations/2002/2 "2020-11-10T11:09:37Z")

</div>

Ok after I have added SGS\_KIBANA\_ALL\_WRITE to my role’s tennant permissions it works now

```
{
  "description": "test_role",
  "cluster_permissions": [
    "SGS_CLUSTER_COMPOSITE_OPS",
    "SGS_CLUSTER_COMPOSITE_OPS_RO",
    "SGS_CLUSTER_MONITOR",
    "cluster:monitor/main\""
  ],
  "index_permissions": [
    {
      "index_patterns": [
        "index-*"
      ],
      "fls": [],
      "masked_fields": [],
      "allowed_actions": [
        "SGS_INDICES_MONITOR",
        "SGS_READ",
        "SGS_SEARCH",
        "SGS_UNLIMITED",
        "SGS_WRITE"
      ]
    }
  ],
  "tenant_permissions": [
    {
      "allowed_actions": [
        "SGS_KIBANA_ALL_WRITE",
        "SGS_SIGNALS_ALL"
      ],
      "tenant_patterns": [
        "SGS_GLOBAL_TENANT"
      ]
    }
  ]
}

```

Why do I need to configure tennant permissions if I did not activated the usage of tennant in the searchguard config?

---

<div class="post-metadata">

**Author:** ![srgbnd](https://sea1.discourse-cdn.com/flex019/user_avatar/forum.search-guard.com/srgbnd/32/506_2.png) [@srgbnd](https://forum.search-guard.com/u/srgbnd)\
**Post date:** [November 10, 2020, 11:42am UTC](https://forum.search-guard.com/t/not-enough-permissions-for-saving-visualizations/2002/3 "2020-11-10T11:42:31Z")

</div>

Hi. The multitenancy is always there, even if you have it disabled. If you have it disabled, you have the default tenant context `_main` for all. That’s why adding the SGS\_KIBANA\_ALL\_WRITE action group worked for you.

To save a visualization, you need access to the kibana.index which has the default value .kibana. Because Kibana saves its objects there. Put `.kibana*` in the index\_permissions.index\_patterns.

You can see all the single permissions assigned to an action group in the Search Guard configuration UI.

 ![Screenshot 2020-11-10 at 12.41.21](https://us1.discourse-cdn.com/flex019/uploads/search_guard/original/1X/15995f43366650da03cc51ebbe627147c627bd17.png)

---

<div class="post-metadata">

**Author:** ![system](https://sea1.discourse-cdn.com/flex019/user_avatar/forum.search-guard.com/system/32/1870_2.png) [@system](https://forum.search-guard.com/u/system)\
**Post date:** [December 1, 2020, 11:42am UTC](https://forum.search-guard.com/t/not-enough-permissions-for-saving-visualizations/2002/4 "2020-12-01T11:42:33Z")

</div>

This topic was automatically closed 21 days after the last reply. New replies are no longer allowed.
