Skip to content

[Request] Cases subfeatures #6266

@kqualters-elastic

Description

@kqualters-elastic

Description

2 new cases sub features were added for 8.17: re-opening cases and adding comments/attachments to cases. These privs can be configured for Security, Observability, and Stack Management cases.

  • Re-open: Controls the ability to re-open cases.
    • When Cases has the read permission, and the reopen permission is not enabled, users have permissions as before. (Meaning they can't re-open a case?)
    • When enabled (with what level of privs, read or all?), users can move cases from closed to open/in progress, but nothing else (Meaning they can't move the case status to Closed?).
    • If a user has All and this priv enabled, they can do anything as before (?).
    • If a user has All (?) and the option is unselected, they can change case properties, and change a case from open to anything, in progress to anything. However, if the case is closed, they cannot reopen it. (need to test)
  • Create comments & attachments: When enabled and the user has case Read privs, users can add comments, but not make any other changes to the case.
    • When the user has Read and this priv deselected, read functions as before (?).
    • When a user has All and this priv selected, this functions as all (?).
    • When a user has All and this priv deselected, the user can do everything normally, except add cases comments.

Image

Impacted Security docs

Background & resources

Which documentation set does this change impact?

ESS and serverless

ESS release

N/A

Serverless release

November 26th, 2024

Feature differences

N/A

API docs impact

N/A

Prerequisites, privileges, feature flags

No response

Metadata

Metadata

Labels

Effort: MediumIssues that take moderate but not substantial time to completeFeature: CasesCases issuesPriority: HighIssues that are time-sensitive and/or are of high customer importanceTeam: Threat HuntingFormerly Data Visibilityv8.17.0

Type

No type

Projects

No projects

Milestone

No milestone

Relationships

None yet

Development

No branches or pull requests

Issue actions