﻿---
title: Security Kibana privileges
description: Lists Kibana privileges in the Security group of Assign role to spaces, with privilege levels and links to sub-feature catalogs.
url: https://docs-v3-preview.elastic.dev/elastic/docs-content/pull/8281/solutions/security/get-started/security-kibana-privileges
products:
  - Elastic Cloud Serverless
  - Elastic Security
applies_to:
  - Serverless Security projects: Generally available
  - Elastic Stack: Generally available
---

# Security Kibana privileges
Roles control what users can access and what actions they can perform. When you create or edit a role, you grant it [Kibana privileges](https://docs-v3-preview.elastic.dev/elastic/docs-content/pull/8281/deploy-manage/users-roles/cluster-or-deployment-auth/kibana-privileges), which give access to individual features within one or more spaces.
To create or edit a role, find **Roles** in the navigation menu or by using the [global search field](https://docs-v3-preview.elastic.dev/elastic/docs-content/pull/8281/explore-analyze/find-and-organize/find-apps-and-objects). Adding Kibana privileges opens the **Assign role to spaces** flyout, where features are grouped by solution. Access to Elastic Security features is controlled by the **Security** group privileges, described on this page.
For more details on using this UI, refer to [Role management using Kibana](https://docs-v3-preview.elastic.dev/elastic/docs-content/pull/8281/deploy-manage/users-roles/cluster-or-deployment-auth/kibana-role-management) for Elastic Stack, or to [Custom roles](https://docs-v3-preview.elastic.dev/elastic/docs-content/pull/8281/deploy-manage/users-roles/cloud-organization/user-roles) for Serverless.

## Access levels

For each of the feature privileges, select the type of access you want to allow:
- **All**: Users have full access to the feature, which includes performing all available actions and managing configuration.
- **Read**: Users can view the feature, but can't perform any actions or manage configuration.
- **None**: Users can't access or view the feature.

<note>
  Some features don't have a **Read** privilege.
</note>


## Privileges in the Security group

Each of the following privileges controls access to a different part of Elastic Security.
<table>
  | Privilege                                                                                                                                                                                               | What it allows                                                                                                                                                                                                                                                                                                                                                                                                                                                                              |
  |---------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------|---------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------|
  | **Security**                                                                                                                                                                                            | Access the Elastic Security features that don't have a privilege of their own. Turn on **Customize sub-feature privileges** to grant individual privileges. Refer to [Security sub-feature privileges](#security-sub-feature-privileges). <applies-to>Elastic Stack: Generally available from 9.0 to 9.2</applies-to> **Security** also allows access to detection rules, alerts, and exceptions.                                                                                           |
  | **Cases**                                                                                                                                                                                               | Access cases. Turn on **Customize sub-feature privileges** to grant individual case privileges. For the full list, refer to [Customize sub-feature privileges for cases](/elastic/docs-content/pull/8281/explore-analyze/cases/control-case-access#cases-sub-feature-privileges).                                                                                                                                                                                                           |
  | **Timeline**                                                                                                                                                                                            | Access [Timeline](https://docs-v3-preview.elastic.dev/elastic/docs-content/pull/8281/solutions/security/investigate/timeline).                                                                                                                                                                                                                                                                                                                                                              |
  | **Notes**                                                                                                                                                                                               | Access [Notes](https://docs-v3-preview.elastic.dev/elastic/docs-content/pull/8281/solutions/security/investigate/notes).                                                                                                                                                                                                                                                                                                                                                                    |
  | **Rules and Exceptions** <applies-to>Elastic Stack: Generally available since 9.4</applies-to> <applies-to>Elastic Cloud Serverless: Generally available</applies-to>                                   | Access detection rules and exceptions, including the Rules table, rule details, and rule monitoring. Turn on **Customize sub-feature privileges** to grant individual rule and exception privileges. For the full list, refer to [Rules and Exceptions sub-feature privileges](#rules-and-exceptions-sub-feature-privileges).                                                                                                                                                               |
  | **Alerts** <applies-to>Elastic Stack: Generally available since 9.4</applies-to> <applies-to>Elastic Cloud Serverless: Generally available</applies-to>                                                 | Access [detection alerts](https://docs-v3-preview.elastic.dev/elastic/docs-content/pull/8281/solutions/security/detect-and-alert/manage-detection-alerts).                                                                                                                                                                                                                                                                                                                                  |
  | **Rules, Alerts, and Exceptions** <applies-to>Elastic Stack: Deprecated since 9.4, Elastic Stack: Generally available in 9.3</applies-to> <applies-to>Elastic Cloud Serverless: Deprecated</applies-to> | Access detection rules, alerts, and exceptions. Roles that use this privilege keep working, but the privilege is no longer available. Use **Rules and Exceptions** and **Alerts** instead.                                                                                                                                                                                                                                                                                                  |
  | **Elastic AI Assistant**                                                                                                                                                                                | Access [Elastic AI Assistant](https://docs-v3-preview.elastic.dev/elastic/docs-content/pull/8281/solutions/security/ai/ai-assistant). Turn on **Customize sub-feature privileges** to grant individual AI Assistant privileges. For the full list, refer to [Elastic AI Assistant sub-feature privileges](#elastic-ai-assistant-sub-feature-privileges).                                                                                                                                    |
  | **Attack discovery**                                                                                                                                                                                    | Access [Attack Discovery](https://docs-v3-preview.elastic.dev/elastic/docs-content/pull/8281/solutions/security/ai/attack-discovery). <applies-to>Elastic Stack: Generally available since 9.1</applies-to> <applies-to>Elastic Cloud Serverless: Generally available</applies-to> Turn on **Customize sub-feature privileges** to grant individual Attack discovery privileges. For details, refer to [Attack discovery sub-feature privileges](#attack-discovery-sub-feature-privileges). |
  | **Automatic Migration**                                                                                                                                                                                 | Access [Automatic Migration](https://docs-v3-preview.elastic.dev/elastic/docs-content/pull/8281/solutions/security/get-started/automatic-migration).  <applies-to>Elastic Stack: Generally available from 9.0 to 9.2</applies-to> This privilege is called **SIEM migrations**.                                                                                                                                                                                                             |
</table>


## Security sub-feature privileges

Unlike the other features in this group, selecting **All** for **Security** doesn't include its sub-feature privileges. You grant each one separately.
Most of the **Security** privileges control Elastic Defend features. For the full list, refer to [Elastic Defend sub-feature privileges](https://docs-v3-preview.elastic.dev/elastic/docs-content/pull/8281/solutions/security/configure-elastic-defend/elastic-defend-feature-privileges). The following table lists the rest.
<table>
  | Privilege                                                                                                                                                       | What it allows                                                                                                                                   |
  |-----------------------------------------------------------------------------------------------------------------------------------------------------------------|--------------------------------------------------------------------------------------------------------------------------------------------------|
  | **SOC Management** <applies-to>Elastic Stack: Generally available since 9.3</applies-to> <applies-to>Elastic Cloud Serverless: Generally available</applies-to> | Access the [Value report](https://docs-v3-preview.elastic.dev/elastic/docs-content/pull/8281/solutions/security/ai/ease/ease-value-report) page. |
</table>


## Rules and Exceptions sub-feature privileges

<applies-to>
  - Elastic Cloud Serverless: Generally available
  - Elastic Stack: Generally available since 9.4
</applies-to>

These privileges control specific actions on detection rules and exceptions. Selecting **All** includes everything in the following table.
<table>
  | Privilege                     | What it allows                                                                                                                                                                                        |
  |-------------------------------|-------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------|
  | **Exceptions**                | Create and manage exceptions for rules and shared exception lists. If this privilege is cleared, users with **Read** for **Rules and Exceptions** can still view exception lists and exception items. |
  | **Investigation guides**      | Create and edit [investigation guides](https://docs-v3-preview.elastic.dev/elastic/docs-content/pull/8281/solutions/security/detect-and-alert/write-investigation-guides) on custom rules.            |
  | **Custom highlighted fields** | Add and edit [custom highlighted fields](/elastic/docs-content/pull/8281/solutions/security/detect-and-alert/common-rule-settings#rule-ui-advanced-params) on rules.                                  |
  | **Enable or Disable**         | Enable and disable detection rules.                                                                                                                                                                   |
  | **Manual rule run**           | [Manually run rules](/elastic/docs-content/pull/8281/solutions/security/detect-and-alert/manage-detection-rules#manually-run-rules) for a selected time range.                                        |
  | **Rule management settings**  | Change **Settings** above the Rules table, including options that affect gap monitoring.                                                                                                              |
</table>


## Elastic AI Assistant sub-feature privileges

These privileges control changes to AI Assistant settings. Selecting **All** includes everything in the following table.
<table>
  | Privilege                             | What it allows                                                                                                                                                                                                                                                                                                                                |
  |---------------------------------------|-----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------|
  | **Field Selection and Anonymization** | Change which alert fields [Elastic AI Assistant](https://docs-v3-preview.elastic.dev/elastic/docs-content/pull/8281/solutions/security/ai/ai-assistant) and [Attack Discovery](https://docs-v3-preview.elastic.dev/elastic/docs-content/pull/8281/solutions/security/ai/attack-discovery) can use, and anonymize the content of those fields. |
  | **Knowledge Base**                    | Change global [Knowledge Base](https://docs-v3-preview.elastic.dev/elastic/docs-content/pull/8281/solutions/security/ai/ai-assistant-knowledge-base) entries, which apply to everyone in the space, including entries that other users created.                                                                                               |
</table>


## Attack discovery sub-feature privileges

<applies-to>
  - Elastic Cloud Serverless: Generally available
  - Elastic Stack: Generally available since 9.1
</applies-to>

These privileges control specific Attack Discovery actions. Selecting **All** includes everything in the following table.
<table>
  | Privilege     | What it allows                                                                                                                                                                                                     |
  |---------------|--------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------|
  | **Schedules** | Create, edit, enable, disable, and delete [Attack Discovery schedules](https://docs-v3-preview.elastic.dev/elastic/docs-content/pull/8281/solutions/security/ai/attack-discovery/schedule-runs-from-attacks-page). |
</table>