elastic / elastic/docs-content
[Internal]: Document the Synthetics “Can run tests manually” sub-feature privilege
- Dominant language
- No language data
- Stars
- 47
- Forks
- 261
- Avg merge
- 3d 21h
- Merged PRs (30d)
- 141
Description
### Description
[elastic/kibana#282149](https://github.com/elastic/kibana/pull/282149) adds an opt-in **Can run tests manually** Synthetics sub-feature privilege. It lets an administrator grant a read-only Synthetics user permission to trigger an on-demand run of an existing monitor without also granting permission to create, edit, or delete monitors.
- **What:** In Kibana role management, an administrator grants the base **Synthetics and Uptime: Read** privilege and enables the **Can run tests manually** sub-feature. That user can then use **Run test manually** from a monitor action.
- **Why:** Today, running an on-demand test requires the broad Synthetics write privilege. The new sub-feature supports least-privilege roles for operators who must launch an ad-hoc run but must not manage monitors.
- **Behavior:** A user with read only cannot run a test. An existing Synthetics `all` role continues to be able to run tests through its existing write privilege; no current role loses access. The manual-run sub-feature is opt-in and does not grant monitor CRUD or other Synthetics write capabilities.
_Docs impact:_ Update [Reader role](https://www.elastic.co/docs/solutions/observability/synthetics/reader-role) (`solutions/observability/synthetics/reader-role.md`) with an optional least-privilege variation for users who need to view Synthetics and manually run existing monitors. Use the product labels **Can run tests manually** (role management) and **Run test manually** (monitor action).
### Resources
- Implemented in: https://github.com/elastic/kibana/pull/282149
- Kibana issue created in error for this request: https://github.com/elastic/kibana/issues/290744
### Which deployment methods does this change impact?
Elastic On-Prem and Cloud (all)
### Feature differences
The privilege is intended to behave the same in stateful and serverless Observability deployments. The implementation includes authorization coverage for both.
### What Elastic Stack release is this request related to?
8.19.22, 9.4.7, 9.5.4, and 9.6. Update the applicable versioned documentation.
### Serverless release
Available with the corresponding deployment release; confirm the production rollout date before publishing release-specific wording.
### Collaboration model
The product or engineering team will create the first draft
### Point of contact
**Main contact:** @shahzad31
### Suggested acceptance criteria
- [ ] The reader-role documentation shows the role combination needed for on-demand monitor runs.
- [ ] It clearly distinguishes manual-run access from monitor write/CRUD access.
- [ ] The role-management and monitor-action labels match the product.
- [ ] Version availability is accurate.
Contributor guide
No contributing guide indexed for this repository
Research direction
Start with solutions/observability/synthetics/reader-role.md and review the existing Reader role guidance. Add the optional role combination using the labels “Can run tests manually” and “Run test manually,” distinguishing it from monitor write/CRUD access. Confirm the applicable version availability and rollout wording with the listed contact, then verify all acceptance criteria.
Written by the indexing model from the issue text.
Assessment
- Domain
- documentation
- Issue type
- Documentation
- Difficulty
- 2/5
- Estimated time
- 1-3 hours
- Activity status
- Active
- Clarity
- Mostly clear
- Newbie friendliness
- 76/100