# Updating roles

**URL:** <https://discuss.elastic.co/t/updating-roles/81025>\
**Category:** Elasticsearch\
**Created:** [April 3, 2017, 3:40pm UTC](https://discuss.elastic.co/t/updating-roles/81025 "2017-04-03T15:40:11Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![YvorL](https://avatars.discourse-cdn.com/v4/letter/y/9fc348/32.png) [@YvorL](https://discuss.elastic.co/u/YvorL)\
**Post date:** [April 3, 2017, 3:40pm UTC](https://discuss.elastic.co/t/updating-roles/81025/1 "2017-04-03T15:40:11Z")

</div>

I'm trying to create some roles to define specific access to Kibana and its features, but I have the following issue:  
When I add a role, I check how it's working then I need to adjust it to the achieve my goal. But I get this message:  
"transient\_metadata" is not allowed  
and can't modify it. I also tried to add a 'Role' via the 'Dev Tools' panel and adding this property, but the result was same.

Also, I didn't find a clear document how can I restrict/allow access to Kibana for other users. I read the docs on /guide, but those didn't help out my case.

---

<div class="post-metadata">

**Author:** ![Marius\_Dragomir](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/marius_dragomir/32/42087_2.png) [@Marius\_Dragomir](https://discuss.elastic.co/u/Marius_Dragomir)\
**Post date:** [April 10, 2017, 12:39pm UTC](https://discuss.elastic.co/t/updating-roles/81025/2 "2017-04-10T12:39:21Z")

</div>

Hello,  
What versions of Kibana/ES/X-Pack are you using?

---

<div class="post-metadata">

**Author:** ![YvorL](https://avatars.discourse-cdn.com/v4/letter/y/9fc348/32.png) [@YvorL](https://discuss.elastic.co/u/YvorL)\
**Post date:** [April 12, 2017, 12:57pm UTC](https://discuss.elastic.co/t/updating-roles/81025/3 "2017-04-12T12:57:06Z")

</div>

Fortunately, updating all versions to the latest solved the issue.

I'd like to move to the next part 🙂

So, I'd like to create a role which can "read" only 'myindex\*':

- browse in "Discovery"
- load saved visualizations (can modify the search bar)
- same with dashboards
- monitoring the cluster

And nothing else (at least now).

---

<div class="post-metadata">

**Author:** ![Marius\_Dragomir](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/marius_dragomir/32/42087_2.png) [@Marius\_Dragomir](https://discuss.elastic.co/u/Marius_Dragomir)\
**Post date:** [April 13, 2017, 4:47pm UTC](https://discuss.elastic.co/t/updating-roles/81025/4 "2017-04-13T16:47:25Z")

</div>

You are going to need to add kibana\_user as a permission in order for him to use Kibana, but maybe creating a role shadowing this one, only with read permissions on the .kibana index and "myindex\*". I

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [May 11, 2017, 4:49pm UTC](https://discuss.elastic.co/t/updating-roles/81025/5 "2017-05-11T16:49:02Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
