elastic / elastic/docs-content

[Internal]: Watchlist write operations now require Security:all privilege

Open Beginner friendly
#6,982 2 comments 0 reactions 0 assignees View on GitHub
documentation Team:Experience triaged
Dominant language
No language data
Stars
47
Forks
261
Avg merge
3d 12h
Merged PRs (30d)
116

Description

### Description

**What**
The Saved Objects security extension is now enforced on Watchlist routes. As a result, users with the _Security:read_ privilege can still read watchlists and watchlist entity sources but can no longer create, update, delete, sync, install prebuilt watchlists, or manage entity sources / entity assignments. These write operations now require the _Security:all_ privilege (specifically, write access to the Security Solution feature, which carries the entity-analytics sub-feature)

Probably add a Privileges section similar to https://www.elastic.co/docs/solutions/security/advanced-entity-analytics/entity-risk-scoring-requirements#_privileges_2 on the [watchlists documentation](https://www.elastic.co/docs/solutions/security/advanced-entity-analytics/watchlists)

**When**
Merged to 9.5.0 and backported to 9.4.3

**Why**
This corrects a previously privilege gap where `Security:read` users could perform write operations on Watchlist saved objects because the Saved Objects security extension had been disabled on these routes.

### Resources

This feature was implemented in: https://github.com/elastic/kibana/pull/270292

### Which deployment methods does this change impact?

Elastic On-Prem and Cloud (all)

### Feature differences

_No response_

### What Elastic Stack release is this request related to?

9.4

### Serverless release

Next release

### Collaboration model

Unknown

### Point of contact.

**Main contact:** `@tcalopes`

**Stakeholders:** `@jaredburgettelastic`

TriageBot — Complete

### 2026-06-26

**Type:** documentation

**Section check:**
- ✅ What is missing: Clearly stated (Privileges section needed on watchlists docs)
- ✅ Problem statement: Explains the privilege change and why docs update is needed
- ✅ Definition of done: Add Privileges section similar to entity risk scoring requirements page

**Cross-references:**
- https://www.elastic.co/docs/solutions/security/advanced-entity-analytics/entity-risk-scoring-requirements#_privileges_2 — reference implementation for the new section
- https://www.elastic.co/docs/solutions/security/advanced-entity-analytics/watchlists — target documentation page
- https://github.com/elastic/kibana/pull/270292 — upstream Kibana implementation PR

**Next step:** none — issue is complete

> Generated by [Gh Aw Issue Triage](https://github.com/elastic/docs-content/actions/runs/28258740336) for issue #6982 · 27.1 AIC · ⌖ 10.1 AIC · ⊞ 9.1K · [◷](https://github.com/search?q=repo%3Aelastic%2Fdocs-content+is%3Aissue+%22gh-aw-workflow-call-id%3A+elastic%2Fdocs-content%2Fgh-aw-issue-triage%22&type=issues)

Contributor guide

No contributing guide indexed for this repository

Research direction

Open the watchlists documentation page and compare its privileges guidance with the Privileges section on the entity risk scoring requirements page. Document that read access remains available with Security:read while watchlist and entity-source write operations require Security:all, including the Security Solution feature access. Done when the watchlists page explains these requirements for the affected releases.

Written by the indexing model from the issue text.

Assessment

Domain
documentation
Issue type
Documentation
Difficulty
2/5
Estimated time
1-3 hours
Activity status
Quiet
Clarity
Clearly specified
Newbie friendliness
72/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.