A crude workaround will be to query the current user's search filter using REST endpoints and then filter your lookup manually using the results. Please note the this query will be run with current user's account so that they should have proper capabilities to run those
| inputlookup role-lookup.csv | search | rest /services/authentication/current-context splunk_server=local | table title roles | mvexpand roles | append[| rest /services/authorization/roles splunk_server=local | table title srchFilter | rename title as roles ] | stats values(title) as user values(srchFilter) as search by roles | where isnotnull(user) | table search]
Other option would be to use this search and create scheduled saved search to populate another lookup and use that instead to filter records. Again, it will not filter automatically, you need to include it in your search.
Thanks, I was afraid I would have to do something like this. Its a bit too complex and has a too many dependencies to be worth using in a simple dashboard dropdown for my use case, but it might solve someone elses problem.