Limited access user : role 'kibana_user' can still manage spaces

Hi,

thanks for your answer,
I understand that from several roles, the union will be applied. Since 'kibana_user' gives 'admin' rights on Kibana app, spaces will be configurable by this user.

So the problem here is what role / rights shall I assign to the user so that it can use Kibana features discover/visualize/dashboard, only over a set of given spaces (and associated index patterns), without giving the right to administrate Kibana app, nor interfer on spaces/indices he shall not have access to.

I tried to set-up privileges as tights as I could as described in my initial message, as far as I understood security features in Kibana, but could not manage to get such a result.

From this example, if I remove the 'kibana_user' role, GUI seems to be as expected, but then when using it some error pops-up ("Error fetching fields for index pattern xxx : Forbidden"), even if the user roles give access to related user index and .kibana* indices.

In short, is there a role giving full access to discover/visualize/dashboard apps without giving admin rights on 'Kibana app'?

Thx again for your help!

by the way, the link you gave in previous answer seems to be outdated, get page with text "Moved Permanently. Redirecting to /fr/opt/node_apps/new404.html](https://www.elastic.co/fr/opt/node_apps/new404.html"