Control access to cases
To manage cases, users need the appropriate Kibana feature privileges. You can grant different levels of access depending on what users need to do, from full control over cases to view-only access.
The following table shows the minimum privileges required for each activity. Higher privilege levels include the access shown here. Set Cases privileges under your solution (Stack Management, Security, or Observability). Refer to the following sections for the full breakdown.
| To... | Minimum required privilege |
|---|---|
| View cases | Cases: Read |
| Create and manage cases | Cases: All |
| Be assigned to cases | Cases: All (user must also log in at least once) |
| Manage connectors and push cases externally | Cases: All + Actions and Connectors: All (under Management) |
| Manage case templates and the field library
|
Cases: All + Manage templates sub-feature privilege |
| Add alerts to cases | Cases: All + alert privileges for your solution (see Give access to add alerts to cases) |
Create or update a role, then set Cases privileges under your solution (Stack Management, Security, or Observability). To grant individual privileges, turn on Customize sub-feature privileges. For details about feature and sub-feature privileges, refer to Kibana privileges.
Create a custom role, then set Cases privileges under your solution (Security or Observability). To grant individual privileges, turn on Customize sub-feature privileges.
When Customize sub-feature privileges is on for Cases, you can grant these privileges individually. For details about feature and sub-feature privileges, refer to Kibana privileges.
| Privilege | Description |
|---|---|
| Delete | Delete cases and comments. |
| Case settings | Edit case settings. |
| Create comments & attachments | Add comments to cases. |
| Re-open | Re-open closed cases. |
| Assign users | Assign users to cases. |
| Manage templates
|
Manage case templates. |
Allfor the Cases feature under the appropriate solution (Stack Management, Security, or Observability). This grants full control over cases, including creating, deleting, and editing case settings. You can turn on Customize sub-feature privileges to limit access.Allfor the Actions and Connectors feature under Management. This is required to create, add, delete, and modify connectors that push cases to external systems.
Allfor the Cases feature under the appropriate solution (Security or Observability).Allfor the Actions and Connectors feature under Management. This is required to create, add, delete, and modify case connectors and send updates to external systems.
All for the Cases feature under the appropriate solution (Stack Management, Security, or Observability).
Users must log in to their deployment at least once before they can be assigned to cases. Logging in creates the required user profile.
All for the Cases feature under the appropriate solution (Security or Observability).
Users must log in to their deployment at least once before they can be assigned to cases. Logging in creates the required user profile.
Read for the Cases feature under the appropriate solution (Stack Management, Security, or Observability).
Read for the Cases feature under the appropriate solution (Security or Observability).
To create, edit, delete, import, and export case templates and field library entries, grant the following privileges. Users without Manage templates can still select and apply enabled templates when creating or updating a case.
- Set
Allfor the Cases feature under the appropriate solution (Stack Management, Security, or Observability). - Turn on Customize sub-feature privileges.
- Enable Manage templates.
- Set
Allfor the Cases feature under the appropriate solution (Security or Observability). - Turn on Customize sub-feature privileges.
- Enable Manage templates.
Allfor the Cases feature under the appropriate solution (Security or Observability).- To work with alerts in cases:
- Security:
ReadorAllfor the Security → Alerts feature. For what each level allows, refer to Detections privileges. - Observability:
Readfor Observability
- Security:
Allfor the Cases feature under the appropriate solution (Security or Observability).Readfor a solution that has alerts (for example, Observability or Security).
None for the Cases feature under the appropriate solution (Stack Management, Security, or Observability).
None for the Cases feature under the appropriate solution (Security or Observability).