# Elastic APM service groups permissions

**URL:** <https://discuss.elastic.co/t/elastic-apm-service-groups-permissions/361523>\
**Category:** APM\
**Tags:** ui\
**Created:** [June 14, 2024, 6:12pm UTC](https://discuss.elastic.co/t/elastic-apm-service-groups-permissions/361523 "2024-06-14T18:12:11Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![Gustavo\_Zacarias](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/gustavo_zacarias/32/135311_2.png) [@Gustavo\_Zacarias](https://discuss.elastic.co/u/Gustavo_Zacarias)\
**Post date:** [June 14, 2024, 6:12pm UTC](https://discuss.elastic.co/t/elastic-apm-service-groups-permissions/361523/1 "2024-06-14T18:12:11Z")

</div>

Hi.  
We're currently running on 8.13.4 and service groups are really handy.

However we're facing one issue related to permissions.  
It seems, outside being superuser, that we can't make them show up for regular users.

We're currently using Observability-\>APM-\>Read permissions in kibana, plus read on all the relevant apm indices/datastreams per [APM reader user | Kibana Guide [8.14] | Elastic](https://www.elastic.co/guide/en/kibana/current/apm-app-reader.html) which allows them to see all APM-related data.

Maybe the groups are stored somewhere else that i'm missing?  
Thanks.  
Regards.

---

<div class="post-metadata">

**Author:** ![Ben\_Wolstencroft](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ben_wolstencroft/32/135422_2.png) [@Ben\_Wolstencroft](https://discuss.elastic.co/u/Ben_Wolstencroft)\
**Post date:** [June 20, 2024, 8:40am UTC](https://discuss.elastic.co/t/elastic-apm-service-groups-permissions/361523/2 "2024-06-20T08:40:26Z")

</div>

Not helpful i know but we're also seeing the same issue.

We're fairly convinced that it is a permissions issue but specifically not related to index permissions, as if we give our normal users direct links to service groups they receive 403 errors

---

<div class="post-metadata">

**Author:** ![Kevin\_Noonan](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/kevin_noonan/32/139202_2.png) [@Kevin\_Noonan](https://discuss.elastic.co/u/Kevin_Noonan)\
**Post date:** [November 13, 2024, 11:52pm UTC](https://discuss.elastic.co/t/elastic-apm-service-groups-permissions/361523/3 "2024-11-13T23:52:20Z")

</div>

We too are seeing this. The only work around I can find is giving the reader built in role to my users. This gives a whole lot more then I want to give to my users though.
