# Roles and privileges

**URL:** <https://discuss.elastic.co/t/roles-and-privileges/361611>\
**Category:** Kibana\
**Tags:** kibana-plugin-development, dashboard, visualisation\
**Created:** [June 18, 2024, 4:44am UTC](https://discuss.elastic.co/t/roles-and-privileges/361611 "2024-06-18T04:44:24Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![Anupama2262](https://avatars.discourse-cdn.com/v4/letter/a/8edcca/32.png) [@Anupama2262](https://discuss.elastic.co/u/Anupama2262)\
**Post date:** [June 18, 2024, 4:44am UTC](https://discuss.elastic.co/t/roles-and-privileges/361611/1 "2024-06-18T04:44:24Z")

</div>

I have created a dashboard that I want to integrate into my application. My application already has its own roles and privileges system. I want to filter the data specific to the user ID once they log in to my application, without having to create separate roles and privileges in Kibana. Additionally, what kind of security measures can I use in this scenario?

Hope I am clear with my question

---

<div class="post-metadata">

**Author:** ![carly.richmond](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/carly.richmond/32/104935_2.png) [@carly.richmond](https://discuss.elastic.co/u/carly.richmond)\
**Post date:** [June 18, 2024, 8:37am UTC](https://discuss.elastic.co/t/roles-and-privileges/361611/2 "2024-06-18T08:37:33Z")

</div>

Hi @Anupama2262,

What kind of application are you looking to integrate your application into? If it's JavaScript you can embed the dashboard using an iframe as covered in [this blog](https://www.elastic.co/blog/how-to-embed-kibana-dashboards).

In terms of data filtering you could pass a parameter in the iframe URL to trigger the filters. Authentication-wise, it depends on what system you are using, but I would recommend seeing if either the [anonymous authentication](https://www.elastic.co/guide/en/elasticsearch/reference/current/anonymous-access.html) or [SSO](https://www.elastic.co/guide/en/elasticsearch/reference/current/saml-guide-stack.html) (enterprise feature) options would work for you.

Hope that helps!

---

<div class="post-metadata">

**Author:** ![jsanz](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jsanz/32/53734_2.png) [@jsanz](https://discuss.elastic.co/u/jsanz)\
**Post date:** [June 18, 2024, 9:17am UTC](https://discuss.elastic.co/t/roles-and-privileges/361611/3 "2024-06-18T09:17:43Z")

</div>

adding also to Carly's answer that Elasticsearch supports document-level security (enterprise feature), so if you use SSO with the same groups in your app and Elasticsearch, you should be able to implement read restrictions based on those groups as described here.

> **[Document level security | Elasticsearch Guide \[8.14\] | Elastic](https://www.elastic.co/guide/en/elasticsearch/reference/current/document-level-security.html)**
