Spaces method and path for this operation:
Refer to Spaces for more information.
Replace the per-agent access-control entries. Each entry grants one user a role on this agent. Identify the user by their Kibana user profile uid (id). Entries created before profile uids were adopted may use name (deprecated) instead. The agent owner, cluster admins, and anyone access control grants Manager can call this endpoint. Each call replaces the entire entries list — the most recent successful update wins. To learn more about agents, refer to the agents documentation.
[Required authorization] Route required privileges: agentBuilder:manageAgents.
Responses
-
Indicates a successful response
-
Bad Request — the request body failed validation, or the request targets the built-in Elastic default agent (which cannot have custom access control).
-
Not Found — no agent with this ID is visible to the caller, or the caller lacks write access. Matches the existing
agentNotFoundshape so unprivileged callers cannot probe for hidden agents.
curl \
-X PUT "${KIBANA_URL}/api/agent_builder/agents/{id}/access_control" \
-H "Authorization: ApiKey ${API_KEY}" \
-H "kbn-xsrf: true" \
-H "Content-Type: application/json" \
-d '{
"entries": [
{ "type": "user", "id": "u_alice_profile_uid", "role": "editor" },
{ "type": "user", "id": "u_bob_profile_uid", "role": "user" }
]
}'
PUT kbn://api/agent_builder/agents/{id}/access_control
{
"entries": [
{ "type": "user", "id": "u_alice_profile_uid", "role": "editor" },
{ "type": "user", "id": "u_bob_profile_uid", "role": "user" }
]
}
{
"entries": []
}
{
"entries": [
{
"id": "u_alice_profile_uid",
"role": "editor",
"type": "user"
},
{
"id": "u_bob_profile_uid",
"role": "user",
"type": "user"
}
]
}
{
"access_mode": "private",
"entries": [
{
"added_at": "2026-02-11T10:15:00.000Z",
"id": "u_alice_profile_uid",
"role": "editor",
"type": "user"
},
{
"added_at": "2026-02-11T10:15:00.000Z",
"id": "u_bob_profile_uid",
"role": "user",
"type": "user"
}
]
}
{
"attributes": {
"trace_id": "8d4f2a3b-1c5e-4a9b-9f0d-2e6c1a3d4f5e"
},
"error": "Bad Request",
"message": "The default agent (elastic-ai-agent) does not support custom access controls.",
"statusCode": 400
}
{
"error": "Bad Request",
"message": "[request body.entries]: array size is [101], but cannot be greater than [100]",
"statusCode": 400
}
{
"attributes": {
"trace_id": "8d4f2a3b-1c5e-4a9b-9f0d-2e6c1a3d4f5e"
},
"error": "Not Found",
"message": "Agent custom-agent-id not found",
"statusCode": 404
}