in few words, Splunk don't permit to modify indexed data, so you have only to disable (or not enable) capabilities as knowledge objects creation or modify and log delete.
So you could start to enable:
I don't know what your Apps contain, so e.g. if you have a dashboard that lists Deployment Clients using a REST command, you have to enable a specific feature as "rest_properties_get".
As I said, remember to enable the correct Indexes.
under capabilities tab you can select 'search' for read only to selected indexes. 'schedule_search' if you wish allow the user to schedule searches. Created role shall be assigned to user you wish to allow read permissions.
An upvote would be appreciated if this reply helps!
when you create a new role, skip the first tab (Inheritance) and go directly the the second one (Capabilities), enabling the ones you need.
Remember to enable Indexes otherwise this role will not see anything!