The requirements on security purpose (in readme.md) are much more open than needed. - Specify the scope for each right (maybe only on mysql.*) would be great - As some checks (metrics-mysql-raw.rb) use only the request show global variables, select is not needed (according to https://dev.mysql.com/doc/refman/5.6/en/show-variables.html)