# Space privilege

**URL:** https://discuss.elastic.co/t/space-privilege/328796
**Category:** Kibana
**Created:** [March 29, 2023, 9:14am UTC](https://discuss.elastic.co/t/space-privilege/328796 "2023-03-29T09:14:34Z")
**Posts on this page:** 7
**Page:** 1

<div class="post-metadata">

### Author: ![\_Thomas](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/_thomas/32/82551_2.png) [@\_Thomas](https://discuss.elastic.co/u/_Thomas)
#### Post date: [March 29, 2023, 9:14am UTC](https://discuss.elastic.co/t/space-privilege/328796/1 "2023-03-29T09:14:34Z")

</div>

Hi Guys,  
I'm trying to limit the Space to particular Users - this however, doesn't seem to work the way I'd expect.

The Problem is as following:  
I did create a new Space called "SoC", created a new Role called "TestUser" and assigned the "SoC" Space to the Kibana Privilege.  
My User which I'm testing with, is called "test", and has the Role "TestUser" as well as "editor" assigned.  
So far so good - if I now login with User "test", I do see the following:  
 ![image](https://us1.discourse-cdn.com/elastic/original/3X/4/6/4679e7f11f264dd0948f606a778fd9c180acad33.png)

This User however, should only be able to see the SoC Space, not the Default and SoC. If I click on the SoC space, I'm also able to switch around between the two shown spaces (which also shouldn't be possible).

My Question is:  
How can I restrict this User "test" to only login directly to the SoC Space, and also not being able to switch between the default space and the SoC Space?

We are using the ELK-Stack Version 8.5 - in 6.5 there was a seperate option within the Space creation to restrict spaces, which I now seem not to be able to find.

Any help is much appreciated!

---

<div class="post-metadata">

### Author: ![Tomo\_M](https://avatars.discourse-cdn.com/v4/letter/t/848f3c/32.png) [@Tomo\_M](https://discuss.elastic.co/u/Tomo_M)
#### Post date: [March 29, 2023, 4:24pm UTC](https://discuss.elastic.co/t/space-privilege/328796/2 "2023-03-29T16:24:05Z")

</div>

The privilege for a user is a union of privileges for all roles.  
If "editor" role have privileges for Default space, "test" can access Default space.

---

<div class="post-metadata">

### Author: ![Larry\_Gregory](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/larry_gregory/32/34969_2.png) [@Larry\_Gregory](https://discuss.elastic.co/u/Larry_Gregory)
#### Post date: [March 29, 2023, 4:44pm UTC](https://discuss.elastic.co/t/space-privilege/328796/3 "2023-03-29T16:44:47Z")

</div>

@Tomo_M is exactly right. The built-in `editor` role grants access to all spaces. If you remove that role from your `test` user, then you'll find that Kibana will only permit access to the `SoC` space.

---

<div class="post-metadata">

### Author: ![\_Thomas](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/_thomas/32/82551_2.png) [@\_Thomas](https://discuss.elastic.co/u/_Thomas)
#### Post date: [March 29, 2023, 7:00pm UTC](https://discuss.elastic.co/t/space-privilege/328796/4 "2023-03-29T19:00:40Z")

</div>

Thank you for the heads up.  
But i do Need the Editor role, for the User to be able to create its own Dashboard. I did try to assign the Privileges „viewer“ as well as „monitoring\_user“, which would basically solve my Space issue. Apparently, the User wouldn‘t be able to create dashboards then

---

<div class="post-metadata">

### Author: ![Tomo\_M](https://avatars.discourse-cdn.com/v4/letter/t/848f3c/32.png) [@Tomo\_M](https://discuss.elastic.co/u/Tomo_M)
#### Post date: [March 30, 2023, 12:58am UTC](https://discuss.elastic.co/t/space-privilege/328796/5 "2023-03-30T00:58:56Z")

</div>

First of all, we have to understand roles are not restrictions but privileges. Users with multiple roles are granted access for union of the privileges. Not union of the restrictions. You cannot add any restrictions by just adding some role to some users.

you may need create your own "test-dashboard-editor" role or some which is granted only priviledges you need. Any built-in role may not completely match your need.

---

<div class="post-metadata">

### Author: ![\_Thomas](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/_thomas/32/82551_2.png) [@\_Thomas](https://discuss.elastic.co/u/_Thomas)
#### Post date: [March 30, 2023, 6:23am UTC](https://discuss.elastic.co/t/space-privilege/328796/6 "2023-03-30T06:23:43Z")

</div>

Thank you for your explanation.

I'll go ahead and try to play further around with this.

Appreciate your and @Larry_Gregory help on that one!

---

<div class="post-metadata">

### Author: ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)
#### Post date: [April 27, 2023, 6:24am UTC](https://discuss.elastic.co/t/space-privilege/328796/7 "2023-04-27T06:24:43Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
