elastic / elastic/docs-content
[Internal]: Watchlist write operations now require Security:all privilege
- Dominant language
- No language data
- Stars
- 47
- Forks
- 261
- Avg merge
- 3d 12h
- Merged PRs (30d)
- 116
Description
### Description
**What**
The Saved Objects security extension is now enforced on Watchlist routes. As a result, users with the _Security:read_ privilege can still read watchlists and watchlist entity sources but can no longer create, update, delete, sync, install prebuilt watchlists, or manage entity sources / entity assignments. These write operations now require the _Security:all_ privilege (specifically, write access to the Security Solution feature, which carries the entity-analytics sub-feature)
Probably add a Privileges section similar to https://www.elastic.co/docs/solutions/security/advanced-entity-analytics/entity-risk-scoring-requirements#_privileges_2 on the [watchlists documentation](https://www.elastic.co/docs/solutions/security/advanced-entity-analytics/watchlists)
**When**
Merged to 9.5.0 and backported to 9.4.3
**Why**
This corrects a previously privilege gap where `Security:read` users could perform write operations on Watchlist saved objects because the Saved Objects security extension had been disabled on these routes.
### Resources
This feature was implemented in: https://github.com/elastic/kibana/pull/270292
### Which deployment methods does this change impact?
Elastic On-Prem and Cloud (all)
### Feature differences
_No response_
### What Elastic Stack release is this request related to?
9.4
### Serverless release
Next release
### Collaboration model
Unknown
### Point of contact.
**Main contact:** `@tcalopes`
**Stakeholders:** `@jaredburgettelastic`
TriageBot — Complete
### 2026-06-26
**Type:** documentation
**Section check:**
- ✅ What is missing: Clearly stated (Privileges section needed on watchlists docs)
- ✅ Problem statement: Explains the privilege change and why docs update is needed
- ✅ Definition of done: Add Privileges section similar to entity risk scoring requirements page
**Cross-references:**
- https://www.elastic.co/docs/solutions/security/advanced-entity-analytics/entity-risk-scoring-requirements#_privileges_2 — reference implementation for the new section
- https://www.elastic.co/docs/solutions/security/advanced-entity-analytics/watchlists — target documentation page
- https://github.com/elastic/kibana/pull/270292 — upstream Kibana implementation PR
**Next step:** none — issue is complete
> Generated by [Gh Aw Issue Triage](https://github.com/elastic/docs-content/actions/runs/28258740336) for issue #6982 · 27.1 AIC · ⌖ 10.1 AIC · ⊞ 9.1K · [◷](https://github.com/search?q=repo%3Aelastic%2Fdocs-content+is%3Aissue+%22gh-aw-workflow-call-id%3A+elastic%2Fdocs-content%2Fgh-aw-issue-triage%22&type=issues)
Contributor guide
No contributing guide indexed for this repository
Research direction
Open the watchlists documentation page and compare its privileges guidance with the Privileges section on the entity risk scoring requirements page. Document that read access remains available with Security:read while watchlist and entity-source write operations require Security:all, including the Security Solution feature access. Done when the watchlists page explains these requirements for the affected releases.
Written by the indexing model from the issue text.
Assessment
- Domain
- documentation
- Issue type
- Documentation
- Difficulty
- 2/5
- Estimated time
- 1-3 hours
- Activity status
- Quiet
- Clarity
- Clearly specified
- Newbie friendliness
- 72/100