elastic / elastic/docs-content

[Internal]: Document the Synthetics “Can run tests manually” sub-feature privilege

Open Beginner friendly
#8,287 1 comment 0 reactions 0 assignees View on GitHub
Team:SKI
Dominant language
No language data
Stars
47
Forks
261
Avg merge
3d 21h
Merged PRs (30d)
141

Description

### Description

[elastic/kibana#282149](https://github.com/elastic/kibana/pull/282149) adds an opt-in **Can run tests manually** Synthetics sub-feature privilege. It lets an administrator grant a read-only Synthetics user permission to trigger an on-demand run of an existing monitor without also granting permission to create, edit, or delete monitors.

- **What:** In Kibana role management, an administrator grants the base **Synthetics and Uptime: Read** privilege and enables the **Can run tests manually** sub-feature. That user can then use **Run test manually** from a monitor action.
- **Why:** Today, running an on-demand test requires the broad Synthetics write privilege. The new sub-feature supports least-privilege roles for operators who must launch an ad-hoc run but must not manage monitors.
- **Behavior:** A user with read only cannot run a test. An existing Synthetics `all` role continues to be able to run tests through its existing write privilege; no current role loses access. The manual-run sub-feature is opt-in and does not grant monitor CRUD or other Synthetics write capabilities.

_Docs impact:_ Update [Reader role](https://www.elastic.co/docs/solutions/observability/synthetics/reader-role) (`solutions/observability/synthetics/reader-role.md`) with an optional least-privilege variation for users who need to view Synthetics and manually run existing monitors. Use the product labels **Can run tests manually** (role management) and **Run test manually** (monitor action).

### Resources

- Implemented in: https://github.com/elastic/kibana/pull/282149
- Kibana issue created in error for this request: https://github.com/elastic/kibana/issues/290744

### Which deployment methods does this change impact?

Elastic On-Prem and Cloud (all)

### Feature differences

The privilege is intended to behave the same in stateful and serverless Observability deployments. The implementation includes authorization coverage for both.

### What Elastic Stack release is this request related to?

8.19.22, 9.4.7, 9.5.4, and 9.6. Update the applicable versioned documentation.

### Serverless release

Available with the corresponding deployment release; confirm the production rollout date before publishing release-specific wording.

### Collaboration model

The product or engineering team will create the first draft

### Point of contact

**Main contact:** @shahzad31

### Suggested acceptance criteria

- [ ] The reader-role documentation shows the role combination needed for on-demand monitor runs.
- [ ] It clearly distinguishes manual-run access from monitor write/CRUD access.
- [ ] The role-management and monitor-action labels match the product.
- [ ] Version availability is accurate.

Contributor guide

No contributing guide indexed for this repository

Research direction

Start with solutions/observability/synthetics/reader-role.md and review the existing Reader role guidance. Add the optional role combination using the labels “Can run tests manually” and “Run test manually,” distinguishing it from monitor write/CRUD access. Confirm the applicable version availability and rollout wording with the listed contact, then verify all acceptance criteria.

Written by the indexing model from the issue text.

Assessment

Domain
documentation
Issue type
Documentation
Difficulty
2/5
Estimated time
1-3 hours
Activity status
Active
Clarity
Mostly clear
Newbie friendliness
76/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.