# Give limited access to pmm user while connecting pmm-client to mysql service

**URL:** <https://forums.percona.com/t/give-limited-access-to-pmm-user-while-connecting-pmm-client-to-mysql-service/21829>\
**Category:** Uncategorized\
**Created:** [May 3, 2023, 11:28am UTC](https://forums.percona.com/t/give-limited-access-to-pmm-user-while-connecting-pmm-client-to-mysql-service/21829 "2023-05-03T11:28:10Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![Ayushi-gupta](https://sea1.discourse-cdn.com/flex019/user_avatar/forums.percona.com/ayushi-gupta/32/10280_2.png) [@Ayushi-gupta](https://forums.percona.com/u/Ayushi-gupta)\
**Post date:** [May 3, 2023, 11:28am UTC](https://forums.percona.com/t/give-limited-access-to-pmm-user-while-connecting-pmm-client-to-mysql-service/21829/1 "2023-05-03T11:28:10Z")

</div>

Hello everyone, As I am connecting my pmm-client to the MySQL instance and according to docs when we add pmm-client to mariadb: command is :

GRANT SELECT, PROCESS, SUPER, REPLICATION CLIENT, RELOAD, BACKUP\_ADMIN ON _._ TO ‘pmm’@‘localhost’;

But I want to give pmm-user specific access, not all the access. I don’t want that pmm user to write to any of my databases as somehow my percona server is comprised, it can comprise my database also.

So, can we give some limited access to `pmm-user` to the database or can we give access to `pmm-user` to access only database logs, not the whole database?

---

<div class="post-metadata">

**Author:** ![matthewb](https://sea1.discourse-cdn.com/flex019/user_avatar/forums.percona.com/matthewb/32/34_2.png) [@matthewb](https://forums.percona.com/u/matthewb)\
**Post date:** [May 3, 2023, 4:46pm UTC](https://forums.percona.com/t/give-limited-access-to-pmm-user-while-connecting-pmm-client-to-mysql-service/21829/2 "2023-05-03T16:46:39Z")

</div>

Hello @Ayushi-gupta,  
The GRANT you show has no write permissions to any databases; only read access.

---

<div class="post-metadata">

**Author:** ![Ayushi-gupta](https://sea1.discourse-cdn.com/flex019/user_avatar/forums.percona.com/ayushi-gupta/32/10280_2.png) [@Ayushi-gupta](https://forums.percona.com/u/Ayushi-gupta)\
**Post date:** [May 4, 2023, 5:25am UTC](https://forums.percona.com/t/give-limited-access-to-pmm-user-while-connecting-pmm-client-to-mysql-service/21829/3 "2023-05-04T05:25:48Z")

</div>

So, is not risky to give the pmm server to access read the database? As if the pmm-server is compromised, anyone can read our database. So, can we give only permission for pmm-user to access only logs of database?

---

<div class="post-metadata">

**Author:** ![matthewb](https://sea1.discourse-cdn.com/flex019/user_avatar/forums.percona.com/matthewb/32/34_2.png) [@matthewb](https://forums.percona.com/u/matthewb)\
**Post date:** [May 4, 2023, 2:38pm UTC](https://forums.percona.com/t/give-limited-access-to-pmm-user-while-connecting-pmm-client-to-mysql-service/21829/4 "2023-05-04T14:38:22Z")

</div>

I believe you can restrict SELECT to only `mysql.*`, `information_schema.*`, and `performance_schema.*` The other permissions are global and thus require `*.*`
