[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"skill-elastic-docs-draft-workflow-docs":3,"mdc-lx3679-key":32,"related-repo-elastic-docs-draft-workflow-docs":5304,"related-org-elastic-docs-draft-workflow-docs":5380},{"slug":4,"name":4,"fn":5,"description":6,"org":7,"tags":11,"stars":19,"repoUrl":20,"updatedAt":21,"license":22,"forks":23,"topics":24,"repo":27,"sourceUrl":30,"mdContent":31},"docs-draft-workflow-docs","draft Elastic Workflows documentation","Draft or update Elastic Workflows documentation pages in explore-analyze\u002Fworkflows\u002F — step references, use cases, how-tos, concepts, and overviews. Use when writing Workflows docs, documenting a step type, turning workflow YAML into documentation, drafting from a doc issue in docs-content or docs-content-internal, or creating a new page under the Workflows docset.",{"slug":8,"name":9,"logoUrl":10,"githubOrg":8},"elastic","Elastic","https:\u002F\u002Fpexgzepcugksgbtrxkhf.supabase.co\u002Fstorage\u002Fv1\u002Fobject\u002Fpublic\u002Forg-logos\u002Felastic.png",[12,16],{"name":13,"slug":14,"type":15},"Documentation","documentation","tag",{"name":17,"slug":18,"type":15},"Technical Writing","technical-writing",71,"https:\u002F\u002Fgithub.com\u002Felastic\u002Felastic-docs-skills","2026-07-12T07:48:02.16095",null,9,[25,8,26],"docs","skills",{"repoUrl":20,"stars":19,"forks":23,"topics":28,"description":29},[25,8,26],"Instructions for code agents on how to author Elastic docs","https:\u002F\u002Fgithub.com\u002Felastic\u002Felastic-docs-skills\u002Ftree\u002FHEAD\u002Fskills\u002Fproject\u002Fdocs-draft-workflow-docs","---\nname: docs-draft-workflow-docs\nversion: 1.1.7\ndescription: Draft or update Elastic Workflows documentation pages in explore-analyze\u002Fworkflows\u002F — step references, use cases, how-tos, concepts, and overviews. Use when writing Workflows docs, documenting a step type, turning workflow YAML into documentation, drafting from a doc issue in docs-content or docs-content-internal, or creating a new page under the Workflows docset.\nargument-hint: \u003Cdoc-issue-url-or-page-idea-or-file-path>\ndisable-model-invocation: true\ncontext: fork\nallowed-tools: Read, Grep, Glob, Edit, Write, CallMcpTool, WebFetch, Bash(gh *), AskUserQuestion\nsources:\n  - https:\u002F\u002Fwww.elastic.co\u002Fdocs\u002Fexplore-analyze\u002Fworkflows\n  - https:\u002F\u002Fwww.elastic.co\u002Fdocs\u002Fexplore-analyze\u002Fworkflows\u002Freference\u002Fcheat-sheet\n  - https:\u002F\u002Fwww.elastic.co\u002Fdocs\u002Fexplore-analyze\u002Fworkflows\u002Freference\u002Fstep-types\n  - https:\u002F\u002Fwww.elastic.co\u002Fdocs\u002Fexplore-analyze\u002Fworkflows\u002Fauthoring-techniques\u002Fanatomy\n  - https:\u002F\u002Fwww.elastic.co\u002Fdocs\u002Fcontribute-docs\u002Fcontent-types\u002Fhow-tos\n  - https:\u002F\u002Fwww.elastic.co\u002Fdocs\u002Fcontribute-docs\u002Fcontent-types\u002Foverviews\n  - https:\u002F\u002Fgithub.com\u002Felastic\u002Fkibana\u002Ftree\u002Fmain\u002Fsrc\u002Fplatform\u002Fpackages\u002Fshared\u002Fkbn-workflows\u002Fspec\n  - https:\u002F\u002Fgithub.com\u002Felastic\u002Fkibana\u002Ftree\u002Fmain\u002Fsrc\u002Fplatform\u002Fplugins\u002Fshared\u002Fworkflows_extensions\u002Fdev_docs\n---\n\u003C!-- Copyright Elasticsearch B.V. and\u002For licensed to Elasticsearch B.V. under one\nor more contributor license agreements. See the NOTICE file distributed with\nthis work for additional information regarding copyright\nownership. Elasticsearch B.V. licenses this file to you under\nthe Apache License, Version 2.0 (the \"License\"); you may\nnot use this file except in compliance with the License.\nYou may obtain a copy of the License at\n\n\thttp:\u002F\u002Fwww.apache.org\u002Flicenses\u002FLICENSE-2.0\n\nUnless required by applicable law or agreed to in writing,\nsoftware distributed under the License is distributed on an\n\"AS IS\" BASIS, WITHOUT WARRANTIES OR CONDITIONS OF ANY\nKIND, either express or implied.  See the License for the\nspecific language governing permissions and limitations\nunder the License. -->\n\nYou are a Workflows documentation author for Elastic. Draft or update pages in the **Elastic Workflows** docset (`explore-analyze\u002Fworkflows\u002F` in docs-content). Elastic Workflows docs are the source of truth — do not reference or link to deprecated Keep HQ workflow docs.\n\n## Scope check (required first)\n\nBefore intake, research, or drafting, confirm the request belongs in this skill.\n\n**If the request is not about authoring or updating Elastic Workflows documentation pages, decline immediately.** Explain this skill's scope and stop. Do not run Steps 0–6 for out-of-scope work.\n\n**In scope** — pages under `explore-analyze\u002Fworkflows\u002F` in docs-content:\n\n- Step references (e.g., `workflows\u002Fsteps\u002Fcases.md` for `cases.*` workflow steps)\n- Use cases, how-tos, concepts, overviews, reference pages, and migration guides in the Workflows docset\n- Doc issues whose deliverable is a new or updated Workflows docset page\n\n**Out of scope** — decline rather than reframe:\n\n- General product documentation outside `explore-analyze\u002Fworkflows\u002F` (e.g., Elastic Security Cases UI, Fleet, APM, Kibana app guides)\n- Feature how-tos for using a product in the Kibana UI when the deliverable is not a Workflows documentation page\n- Requests to document workflow YAML or steps as part of a non-Workflows docset\n\nDo **not** satisfy an out-of-scope request by reframing it — for example, turning a Security Cases UI request into a Workflows use-case page, or parking product feature content under a Workflows path for convenience.\n\nWhen declining, respond with:\n\n1. A clear statement that the request is outside this skill's scope\n2. What this skill covers (`explore-analyze\u002Fworkflows\u002F` pages only)\n3. A pointer to the appropriate product docset or docs workflow, without drafting the out-of-scope content\n\nRe-check scope after reading a doc issue in Step 0. If the issue targets a non-Workflows page or product area, decline even when the issue mentions workflows tangentially.\n\n## Inputs\n\n`$ARGUMENTS` is one of:\n\n- A **doc issue** — GitHub issue URL or `owner\u002Frepo#number` (preferred when one exists)\n- A **page idea or outline** (e.g., \"document the `kibana.SetAlertsStatus` step\")\n- A **file path** to draft or update (relative to docs-content or absolute)\n- A **workflow YAML sample** to turn into documentation\n- Any combination of the above in free text\n\nIf empty, start with **Step 0: Intake** — do not jump straight to drafting.\n\n## Companion skills and tools\n\nThis skill works standalone. These optional resources from the [elastic-docs-skills](https:\u002F\u002Fgithub.com\u002Felastic\u002Felastic-docs-skills) catalog improve research and validation — invoke them only if installed; **do not fail the workflow if they are missing**.\n\n| Resource | How to use | Used in |\n|----------|------------|---------|\n| **elastic-docs MCP** | Public HTTP endpoint: `https:\u002F\u002Fwww.elastic.co\u002Fdocs\u002F_mcp\u002F` (no auth). Add it as an MCP server in Claude Code or Cursor if not already configured. Test: `npx @modelcontextprotocol\u002Finspector --url https:\u002F\u002Fwww.elastic.co\u002Fdocs\u002F_mcp\u002F` | Step 2 |\n| **content-type-checker** | `\u002Fcontent-type-checker` — catalog: [skills\u002Fauthoring\u002Fcontent-type-checker](https:\u002F\u002Fgithub.com\u002Felastic\u002Felastic-docs-skills\u002Ftree\u002Fmain\u002Fskills\u002Fauthoring\u002Fcontent-type-checker) | Steps 1, 6 |\n| **docs-syntax-help** | `\u002Fdocs-syntax-help` — catalog: [skills\u002Fauthoring\u002Fdocs-syntax-help](https:\u002F\u002Fgithub.com\u002Felastic\u002Felastic-docs-skills\u002Ftree\u002Fmain\u002Fskills\u002Fauthoring\u002Fdocs-syntax-help) | Step 4 |\n\nInstall a companion skill: `npx skills@latest add elastic\u002Felastic-docs-skills --skill content-type-checker -g`\n\nWhen the elastic-docs MCP is unavailable, fall back to **WebFetch** on `https:\u002F\u002Fwww.elastic.co\u002Fdocs\u002F...` URLs for the same research steps.\n\n## Step 0: Intake from the doc issue\n\nGather scope and resolve open questions before classifying or researching.\n\n### 0a. Get the doc issue\n\nIf `$ARGUMENTS` does not include an issue reference, use `AskUserQuestion`:\n\n> **Do you have a doc issue for this work?** Provide a GitHub issue URL or `elastic\u002Fdocs-content#123` \u002F `elastic\u002Fdocs-content-internal#456`, or choose to proceed without one.\n\nDoc issues live in one of two repos:\n\n| Repo | Use |\n|------|-----|\n| `elastic\u002Fdocs-content` | Public documentation issues |\n| `elastic\u002Fdocs-content-internal` | Internal planning and drafting issues |\n\nAccept:\n\n- Full URL: `https:\u002F\u002Fgithub.com\u002Felastic\u002Fdocs-content\u002Fissues\u002F123` or `https:\u002F\u002Fgithub.com\u002Felastic\u002Fdocs-content-internal\u002Fissues\u002F456`\n- Shorthand: `elastic\u002Fdocs-content#123`, `elastic\u002Fdocs-content-internal#456`, or `docs-content-internal#456`\n- Bare `#123` — **do not assume a repo**; ask which repo via `AskUserQuestion`\n\nIf the user has no issue, skip to Step 1 with whatever context they provide. Note in the output that no issue was supplied.\n\n### 0b. Read the issue\n\nResolve the repo from the issue reference:\n\n1. **Full URL** — extract `docs-content` or `docs-content-internal` from the path\n2. **Shorthand** — use the repo named before `#`\n3. **Bare number** — ask the user to choose `elastic\u002Fdocs-content` or `elastic\u002Fdocs-content-internal`\n\nFetch with the GitHub CLI (substitute the resolved repo):\n\n```bash\ngh issue view \u003Cnumber> --repo elastic\u002Fdocs-content --json title,body,comments,labels\n# or\ngh issue view \u003Cnumber> --repo elastic\u002Fdocs-content-internal --json title,body,comments,labels\n```\n\nBoth repos use the same intake fields and open-question parsing — treat them identically after fetch.\n\nFrom the issue, extract and keep a running **intake summary**:\n\n| Field | Where to look |\n|-------|---------------|\n| Page scope | Title, **Scope**, **Summary**, or first paragraph |\n| Page type | Explicit label, or infer from wording (reference, how-to, use case, etc.) |\n| Target path | File path, proposed location, or linked draft PR |\n| Audience \u002F product area | Labels, body sections, `applies_to` hints |\n| Source material | Linked PRs, Kibana issues, YAML samples, Figma, SME names |\n| Acceptance criteria | Checklist items, \"done when\" statements |\n| **Suggested doc work** | **`## Suggested documentation work (for the writer)`**, **`## Docs work`**, or similar — see Step 0c |\n| **Timeline \u002F release** | `Timeline & environment`, stack version, serverless release date |\n| **Consolidation notes** | `Consolidation notes`, `Reconciled note`, superseded issue references — authoritative maturity wins |\n| **Open questions** | See parsing rules in Step 0d |\n\nAlso read issue **comments** — answers and clarifications to suggested work may already be there.\n\n### 0c. Extract suggested documentation work\n\nLocate the writer brief in the issue `body`. Match any of these headings (case-insensitive):\n\n- `## Suggested documentation work (for the writer)`\n- `## Suggested documentation work`\n- `## Suggested edits`\n- `## Docs work`\n\nIf none of these headings exist, treat numbered deliverables under `## Description` or similarly titled sections as the writer brief when they list concrete file paths and editing tasks.\n\n1. Extract every bullet, checklist item, and numbered task — include sub-bullets and nested items\n2. Parse what each item implies:\n   - **New page** vs **update to existing page** (note file paths when given)\n   - **Mirror page** — when the issue says \"modeled on\" or \"reuse the structure of\" an existing page (e.g., `cases.md`), read that page in Step 2 and match its section order, table layout, and includes\n   - **Multi-file deliverables** — primary page plus hub\u002Findex\u002Fcross-ref updates (e.g., `action-steps.md`, `step-types.md`, `cheat-sheet.md`, sibling step pages)\n   - **Shared conventions** — namespace-wide behavior to document once before per-step sections (bulk IDs, add\u002Fremove semantics, auth model)\n   - **Sections to add** (e.g., \"Add a `Before you begin` section\", \"Document output shape\")\n   - **Examples or YAML** to include — when the issue embeds parameter tables or YAML, treat them as draft input but **verify against Kibana source** in Step 2\n   - **Cross-links**, **preferred-namespace guidance**, or index\u002Fcheat-sheet updates\n   - **Pages to avoid duplicating** or content to remove\n3. Check comments for amendments, deferrals, or scope cuts to these suggestions\n4. Read **Consolidation notes** or **Reconciled note** sections — when an issue supersedes absorbed issues, use this issue's authoritative position for maturity (`applies_to`), availability, and scope. Do not inherit preview\u002FTP labels from closed absorbed issues when the current issue states GA.\n\nTrack each deliverable (not just the primary page) through drafting with status:\n\n| Status | Meaning |\n|--------|---------|\n| **Addressed** | Reflected in the draft |\n| **Deferred** | Out of scope for this pass — note why (user decision or issue comment) |\n| **Blocked** | Cannot draft without unresolved question or missing source |\n\nPresent suggested work in the intake summary before drafting:\n\n```markdown\n## Suggested documentation work\n| # | Suggestion (from issue) | Status |\n|---|-------------------------|--------|\n| 1 | Add example for `workflow.execute` composition | Addressed — see \"Combine actions\" section |\n| 2 | Link from step type index | Deferred — follow-up edit listed below |\n| 3 | Document preview availability | Blocked — awaiting answer to open question #2 |\n```\n\n**Do not invent content that contradicts or ignores these suggestions.** If a suggestion is unclear, ask the user before drafting. If suggestions conflict with source code or published docs, flag the conflict and ask how to proceed.\n\n### 0d. Parse open questions\n\nScan the issue `body` and `comments` for unresolved items. Common locations and formats:\n\n- Headings: `## Open items to confirm before publishing`, `## Open questions`, `## Questions`, `## Unknowns`, `## Decisions needed`\n- Checklist items still open: `- [ ] ...`\n- Explicit markers: `TBD`, `TODO`, `?`, `Need input from`, `Blocked on`\n- Numbered or bulleted questions ending with `?`\n\nFor each question, classify as:\n\n- **Resolved** — answered in the issue body, a comment, or a linked PR\u002Fdescription\n- **Unresolved** — still open or contradictory across comments\n- **Researchable** — answerable from Kibana source or published docs without asking the user (handle in Step 2; do not ask the user)\n\nPresent the parsed list to the user before drafting:\n\n```markdown\n## Intake summary\n- **Issue**: elastic\u002Fdocs-content-internal#456 — \u003Ctitle>\n- **Scope**: ...\n- **Page type**: ...\n- **Target path**: ...\n\n## Suggested documentation work\n| # | Suggestion (from issue) | Status |\n|---|-------------------------|--------|\n| 1 | ... | Addressed \u002F Deferred \u002F Blocked |\n\n## Open questions\n| # | Question | Status |\n|---|----------|--------|\n| 1 | ... | Resolved — see comment by @user |\n| 2 | ... | Unresolved |\n| 3 | ... | Researchable — will verify in Kibana source |\n```\n\n### 0e. Ask the user to answer unresolved questions\n\nIf any questions are **Unresolved**, use `AskUserQuestion` to collect answers. Rules:\n\n- Ask only **unresolved** questions — skip resolved and researchable items\n- Batch related questions in one form when possible (max ~5 per round)\n- Quote the original question text from the issue so the user recognizes it\n- If a question has multiple-choice options implied by the issue, offer those as choices plus **Other**\n\nExample prompt:\n\n> The doc issue lists these open questions. Please answer before I draft:\n> 1. Should this page cover stack 9.4 only or include 9.5+ inputs placement?\n> 2. Is `workflow.executeAsync` in scope or out of scope for this use case page?\n\n**Do not proceed to Step 2 (research) or Step 4 (draft)** until:\n\n- All unresolved questions have answers, **or**\n- The user explicitly says to proceed with stated assumptions (record those assumptions in the output)\n\nAfter answers are collected, update the intake summary and suggested-work status table. If an answer changes page type, target path, or scope of suggested work, re-check classification in Step 1.\n\n## Step 1: Classify the page\n\nDetermine which page type to draft. Use the **intake summary** and **suggested documentation work** from Step 0 when available. Ask one focused question if still unclear.\n\n| Page type | Typical location | Content type | Example |\n|-----------|------------------|--------------|---------|\n| **Step reference** | `explore-analyze\u002Fworkflows\u002Fsteps\u002F` | Reference | Elasticsearch action steps |\n| **Use case** | `explore-analyze\u002Fworkflows\u002Fuse-cases\u002F` | Overview \u002F explanation | Security workflows |\n| **Authoring technique** | `explore-analyze\u002Fworkflows\u002Fauthoring-techniques\u002F` | How-to | Manage and organize workflows |\n| **Concept** | `explore-analyze\u002Fworkflows\u002Fconcepts\u002F` | Explanation | Triggers, Steps, Liquid |\n| **Reference** | `explore-analyze\u002Fworkflows\u002Freference\u002F` | Reference | Cheat sheet, step type index |\n| **Tutorial** | `explore-analyze\u002Fworkflows\u002Fget-started\u002F` | Tutorial | Build your first workflow |\n| **Hub \u002F overview** | `explore-analyze\u002Fworkflows\u002F` or a section index | Overview | Workflows, Use cases |\n\nRun [`\u002Fcontent-type-checker`](https:\u002F\u002Fgithub.com\u002Felastic\u002Felastic-docs-skills\u002Ftree\u002Fmain\u002Fskills\u002Fauthoring\u002Fcontent-type-checker) in classify mode when the page type is ambiguous — skip if not installed.\n\n## Step 2: Research before writing\n\nNever guess step types, parameter names, or UI labels. Gather facts first.\n\n### Published docs (preferred)\n\nUse the **elastic-docs** MCP server at `https:\u002F\u002Fwww.elastic.co\u002Fdocs\u002F_mcp\u002F` (see **Companion skills and tools** for setup). If MCP is unavailable, use WebFetch on the same `https:\u002F\u002Fwww.elastic.co\u002Fdocs\u002F...` URLs.\n\n1. `search_docs` — find existing pages on the topic and related building blocks\n2. `get_document_by_url` — fetch sibling pages, templates, and guidelines with `includeBody: true`\n3. `find_related_docs` — discover cross-link targets\n\nAlways read these anchors before drafting:\n\n| Resource | URL path |\n|----------|----------|\n| Workflows hub | `\u002Fdocs\u002Fexplore-analyze\u002Fworkflows` |\n| Cheat sheet (gotchas) | `\u002Fdocs\u002Fexplore-analyze\u002Fworkflows\u002Freference\u002Fcheat-sheet` |\n| Step type index | `\u002Fdocs\u002Fexplore-analyze\u002Fworkflows\u002Freference\u002Fstep-types` |\n| Anatomy reference | `\u002Fdocs\u002Fexplore-analyze\u002Fworkflows\u002Fauthoring-techniques\u002Fanatomy` |\n| Choose the right step | `\u002Fdocs\u002Fexplore-analyze\u002Fworkflows\u002Fauthoring-techniques\u002Fchoose-the-right-step` |\n\n### Kibana source code\n\nWhen documenting a step type, trigger, or UI workflow:\n\n1. Search the Kibana repo for the step type identifier (e.g., `elasticsearch.search`, `cases.addComment`, `kibana.SetAlertsStatus`, `slack.postMessage`, `foreach`)\n2. Read the step definition, schema, or connector action registration — not just examples\n3. Confirm parameter names, required fields, and output shape\n\nLikely starting points in Kibana — search by step type ID first, then use the path that matches what you are documenting:\n\n| What you need | Where to look |\n|---------------|---------------|\n| **Step parameters, workflow YAML schema, deprecations** | `src\u002Fplatform\u002Fpackages\u002Fshared\u002Fkbn-workflows\u002Fspec\u002F` — start with `schema.ts`, `builtin_step_definitions.ts`, `builtin_trigger_definitions.ts`, and namespace dirs `spec\u002Felasticsearch\u002F`, `spec\u002Fkibana\u002F` |\n| **A specific step type** (`elasticsearch.search`, `cases.addComment`, `security.setAlertStatus`, `kibana.SetAlertsStatus`, `slack.postMessage`, `foreach`, etc.) | `kbn-workflows\u002Fspec\u002F\u003Cnamespace>\u002F` for namespaced steps; `builtin_step_definitions.ts` for built-ins like `foreach`; then the registering plugin via repo search |\n| **Triggers** (manual, scheduled, alert, event-driven) | `kbn-workflows\u002Fspec\u002Fbuiltin_trigger_definitions.ts`; product triggers in registering plugins; `workflows_extensions\u002Fdev_docs\u002FTRIGGERS.md` |\n| **UI labels, step menu, YAML editor, authoring surfaces** | `src\u002Fplatform\u002Fplugins\u002Fshared\u002Fworkflows_management\u002Fpublic\u002F`; server-side step discovery in `workflows_management\u002Fserver\u002F` |\n| **Execution lifecycle, error handling, step output shape** | `src\u002Fplatform\u002Fplugins\u002Fshared\u002Fworkflows_execution_engine\u002F` |\n| **Custom or product-registered steps** | `src\u002Fplatform\u002Fplugins\u002Fshared\u002Fworkflows_extensions\u002F`; internal guide at `workflows_extensions\u002Fdev_docs\u002FSTEPS.md` |\n| **Stack connector actions** | `x-pack\u002Fplatform\u002Fplugins\u002Fshared\u002Fstack_connectors\u002F` and connector-specific plugins under `x-pack\u002Fplatform\u002Fplugins\u002F` |\n\nOfficial example workflows live in `kbn-workflows\u002Fspec\u002Fexamples\u002F`. Prefer these over `elastic\u002Fworkflows` when verifying schema-valid YAML.\n\n**Note:** `x-pack\u002Fplatform\u002Fplugins\u002Fshared\u002Fworkflows\u002F` is a legacy path — use the `src\u002Fplatform\u002F` layout above.\n\n### Existing docs-content files\n\nIf a docs-content checkout exists in the workspace:\n\n- Read sibling pages under `explore-analyze\u002Fworkflows\u002F` for voice, structure, and cross-links\n- Check `explore-analyze\u002Fworkflows\u002F_snippets\u002F` for reusable includes\n- Check `toc.yml` for navigation placement and whether the target is a hub page with `children:`\n\n### Example workflows\n\nThe `elastic\u002Fworkflows` library contains example YAML. Use it for realistic examples, but verify each step type and parameter against source before documenting.\n\n## Step 3: Apply Workflows authoring rules\n\nThese conventions are non-negotiable. The [cheat sheet](https:\u002F\u002Fwww.elastic.co\u002Fdocs\u002Fexplore-analyze\u002Fworkflows\u002Freference\u002Fcheat-sheet) is the authority for gotchas.\n\n### YAML examples\n\n- Use `steps:` blocks for step-focused examples; include full workflow YAML only when triggers, inputs, or settings matter\n- Indent with two spaces; keep examples copy-pasteable\n- Name steps descriptively (`search_for_alerts`, not `step1`)\n- Show data flow between steps explicitly (`steps.\u003Cname>.output`)\n\n### Syntax rules\n\n| Rule | Correct | Wrong |\n|------|---------|-------|\n| Arrays\u002Fobjects in Liquid | `\"${{ event.alerts }}\"` | `\"{{ event.alerts }}\"` |\n| Strings in Liquid | `\"{{ inputs.name }}\"` | — |\n| `data.filter` \u002F `if` conditions | KQL: `item._source.severity : 'critical'` | Liquid: `==` comparisons |\n| Cases step parameters | `case_id`, `comment` (snake_case) | `caseId` (camelCase) |\n| Namespaced step IDs (`cases.*`, `security.*`, `elasticsearch.*`) | Lowercase dot notation: `security.setAlertStatus` | PascalCase (`kibana.SetAlertsStatus`) unless documenting the legacy step itself |\n| Alert status steps | `kibana.SetAlertsStatus` (PascalCase) | `kibana.set_alerts_status` |\n| AI step identifiers | Top-level `connector-id`, `agent-id` (literal kebab-case) | Nested under `with`, or Liquid-templated |\n| JSON serialization | `\\| json`, `\\| json_parse` | `to_json` (does not exist) |\n| `switch.cases` | Array of `{ case:, steps: }` objects | Map\u002Fobject keyed by case value |\n| `workflow.execute` target | `workflow-id` inside `with` | Top-level field |\n\n### Version differences\n\nWhen examples involve `inputs`, show both placements with an applies-switch or tabs:\n\n- **Stack 9.4 and earlier**: top-level `inputs:`\n- **Stack 9.5+ and Serverless**: `inputs` nested under `type: manual` trigger\n\nFetch anatomy.md for the canonical tab markup.\n\n### Lifecycle and availability\n\nNote preview\u002FGA status and `applies_to` tags when a step or feature is version-gated. For deprecated or renamed steps, triggers, or parameters:\n\n- **New content** documents the current replacement, not the deprecated form\n- **Migration context** — if you show a deprecated form, mark it deprecated inline and link to the replacement reference\n- **Migration guides** — search the Workflows docset for version-specific migration pages (e.g., 9.3 → 9.4) and link to them; use `cases.*` instead of `kibana.createCase`-style steps as one example, not the only case\n- **Preferred namespace** — when new namespaced steps (`security.*`, `cases.*`) overlap legacy `kibana.*` PascalCase steps, document the namespaced steps as the preferred path for new workflows and add a cross-reference on the older page (mirror how `kibana.md` points to `cases.*`)\n\n## Step 4: Draft the page\n\nWhen a doc issue was provided, draft content that **addresses every item** in `## Suggested documentation work (for the writer)` unless explicitly deferred. Map each suggestion to a section, example, or follow-up edit in the draft.\n\nFollow the page-type structure in the sections below. H1 patterns, opening paragraphs, and section order are defined there.\n\nWorkflows pages use a small set of MyST directives — apply these directly:\n\n- **Version splits** — `applies-switch` or tabs for YAML that differs by stack\u002Fserverless version (especially `inputs` placement). Copy markup from `anatomy.md`; do not invent tab syntax.\n- **UI walkthroughs** — `stepper` in authoring-technique pages only.\n- **Snippets** — `:::{include}` from `explore-analyze\u002Fworkflows\u002F_snippets\u002F` when a matching snippet exists.\n\nConsult [`\u002Fdocs-syntax-help`](https:\u002F\u002Fgithub.com\u002Felastic\u002Felastic-docs-skills\u002Ftree\u002Fmain\u002Fskills\u002Fauthoring\u002Fdocs-syntax-help) only for a directive you cannot resolve from sibling Workflows pages — skip if not installed.\n\n### Frontmatter\n\n```yaml\n---\nnavigation_title: \u003CShort nav label>   # omit on hub pages when title suffices\ndescription: \u003COne sentence for search and tooltips — include \"workflow\" and the specific topic>\nproducts:\n  - id: kibana\n  - id: cloud-serverless    # include when feature is available on serverless\napplies_to:\n  stack: ga 9.4+            # adjust per feature availability\n  serverless: ga\n---\n```\n\nAdd `type: how-to` or `type: tutorial` when the content type guidelines require it.\n\n### Step reference pages\n\n**File**: `explore-analyze\u002Fworkflows\u002Fsteps\u002F\u003Ctopic>.md` (or a subfolder under `steps\u002F`)\n\nWhen the issue says to model on an existing step page (e.g., Cases action steps), read that sibling page first and mirror its layout rather than inventing a new structure.\n\n**Namespace \u002F action-step family pages** (e.g., `cases.md`, `security.md`, `kibana.md`) use this structure:\n\n1. **H1 + anchor** — name the step family (e.g., \"Security Triage and Investigation action steps\"); set `navigation_title` shorter (e.g., `Security`)\n2. **Introduction** — what the `namespace.*` steps do, when to use them, and how they relate to overlapping steps on other pages\n3. **Shared conventions** — namespace-wide rules before per-step detail:\n   - Parameters under `with`\n   - Single vs bulk ID fields\n   - Add\u002Fremove semantics (preserve existing values; not full replace) when applicable\n   - Required-field rules (e.g., \"at least one of add\u002Fremove\")\n   - Parameter naming differences across related step groups — **document exactly as implemented; do not normalize** (e.g., `alert_ids` vs `ids`, `close_reason` vs `reason`)\n4. **Step catalog** — jump links to each step, grouped by subdomain when helpful (e.g., Alerts vs Attacks)\n5. **Per-step sections** — for each step type:\n   - One-sentence purpose\n   - Parameter table: `Parameter | Location | Type | Required | Description`\n   - YAML example\n6. Include `:::{include} ..\u002F_snippets\u002Fschema-location-legend.md :::` when the mirror page uses it\n7. **Related** — sibling step pages, triggers, step type index, cheat sheet\n\n**Other step reference pages** may also use:\n\n- **Overview table** — step type → API\u002Foperation mapping\n- **Combine actions** — multi-step example showing data flow (search → foreach → action)\n- **Key concepts** — output paths, loop variables, field reads for composition (e.g., reading alert fields before an assign step)\n\nFor a **single step type** addition to an existing namespace page, document:\n\n- Required and optional `with` parameters (table format above)\n- Top-level fields (`connector-id`, `if`, `foreach`, `on-failure`, etc.)\n- Output shape (`steps.\u003Cname>.output`)\n- One minimal example and one realistic multi-step example when helpful\n- Gotchas specific to that step\n\nAfter drafting a new namespace page or step, list follow-up edits for:\n\n- **`steps\u002Faction-steps.md`** — add a category blurb + link when introducing a new step family\n- **`reference\u002Fstep-types.md`** — add rows for every new step type\n- **`reference\u002Fcheat-sheet.md`** — add rows or update task-oriented groupings (e.g., \"Manage alerts\", \"Manage attacks\")\n- **Overlapping sibling pages** — cross-reference preferred namespace (e.g., `kibana.md` → `security.*`)\n\n### Use case pages\n\n**File**: `explore-analyze\u002Fworkflows\u002Fuse-cases\u002F\u003Cdomain>.md`\n\n**Structure**:\n\n1. **H1 + anchor** — domain-focused title (e.g., \"Security workflows\")\n2. **Introduction** — what teams accomplish with workflows in this domain\n3. **Pattern sections** — group by intent, not by step type:\n   - What you can automate (bullet list of outcomes)\n   - Typical triggers and step patterns (brief, with links to step\u002Ftrigger reference)\n   - Pointers to example workflows or templates when they exist\n4. **Related** — links to relevant step references, authoring techniques, and tutorials\n\nUse case pages are shorter than step references. Link out rather than duplicating parameter tables.\n\n### Authoring technique pages (how-tos)\n\n**File**: `explore-analyze\u002Fworkflows\u002Fauthoring-techniques\u002F\u003Caction-verb-topic>.md`\n\nFollow the [how-to content type guidelines](https:\u002F\u002Fwww.elastic.co\u002Fdocs\u002Fcontribute-docs\u002Fcontent-types\u002Fhow-tos):\n\n1. **Action-verb H1** — e.g., \"Monitor workflow execution\"\n2. **Introduction** — outcome the reader will achieve\n3. **Before you begin** — permissions, prerequisites, UI access path\n4. **Numbered steps** — imperative verbs, one action per step; use `stepper` for UI walkthroughs\n5. **Success checkpoints** — how to confirm each critical step worked\n6. **Next steps** and **Related**\n\nKeep how-tos to ≤10 steps. Chain into a tutorial if the scope is broader.\n\n### Concept and reference pages\n\n**Concepts** explain triggers, steps, data flow, Liquid, error handling — focus on mental models and links to reference detail.\n\n**Reference pages** (anatomy, cheat sheet, context variables) use tables, field-by-field descriptions, and version tabs. Prefer tables over prose for parameter catalogs.\n\n### Tutorial pages\n\n**File**: `explore-analyze\u002Fworkflows\u002Fget-started\u002F\u003Ctopic>.md`\n\nFollow tutorial content type guidelines. Chain multiple tasks with explanatory context. Include sample data setup, checkpoints, and a \"what you built\" summary.\n\n## Step 5: Cross-link and navigation\n\nAfter drafting:\n\n1. Add links **to** the new page from hub pages, step type index, cheat sheet, or choose-the-right-step as appropriate\n2. Add a **Related** section at the bottom of the new page (3–5 links)\n3. Update **`steps\u002Faction-steps.md`** when adding a new step family — match existing category blurbs (short description, \"Use … to:\" bullets, `Refer to …` link)\n4. Update **`reference\u002Fstep-types.md`** and **`reference\u002Fcheat-sheet.md`** when the issue lists them as deliverables — do not stop at the primary page draft\n5. Add **preferred-namespace cross-references** on overlapping sibling pages (e.g., steer new alert-triage workflows from `kibana.SetAlertsStatus` to `security.setAlertStatus`)\n6. Update `toc.yml` if adding a new file (confirm placement with the user)\n7. Remove duplicated content from hub pages — hubs summarize and link, they do not restate reference detail\n\n## Step 6: Validate\n\nBefore presenting the draft:\n\n1. Run [`\u002Fcontent-type-checker`](https:\u002F\u002Fgithub.com\u002Felastic\u002Felastic-docs-skills\u002Ftree\u002Fmain\u002Fskills\u002Fauthoring\u002Fcontent-type-checker) on the draft if installed — otherwise spot-check structure against the page-type templates in Step 4\n2. Validate outbound links — use elastic-docs MCP `get_document_by_url` (or WebFetch) to resolve each cross-link in the draft when a file path is available\n3. Spot-check YAML examples against the cheat sheet gotchas list\n4. Confirm step types and parameter names against Kibana source\n5. Cross-check the draft against the **suggested documentation work** table — every non-deferred item must be addressed or explained\n\nReport any items you could not verify against source. Note any companion skills or MCP tools that were unavailable.\n\n## Output format\n\nPresent:\n\n1. **Intake summary** — issue link, scope, **suggested documentation work** (with status per item), resolved and unresolved questions (omit if no issue was used)\n2. **Page classification** — type, target file path, rationale\n3. **Research summary** — source pages read, Kibana files consulted\n4. **Draft content** — full markdown with frontmatter, ready to write to docs-content\n5. **Follow-up edits** — other files to update (index, toc.yml, hub links); include deferred items from suggested doc work\n6. **Open questions** — anything still needing SME review after drafting\n\nIf the user provided a file path, write the draft to that path. Otherwise, propose the path and show the content for review first.\n",{"data":33,"body":48},{"name":4,"version":34,"description":6,"argument-hint":35,"disable-model-invocation":36,"context":37,"allowed-tools":38,"sources":39},"1.1.7","\u003Cdoc-issue-url-or-page-idea-or-file-path>",true,"fork","Read, Grep, Glob, Edit, Write, CallMcpTool, WebFetch, Bash(gh *), AskUserQuestion",[40,41,42,43,44,45,46,47],"https:\u002F\u002Fwww.elastic.co\u002Fdocs\u002Fexplore-analyze\u002Fworkflows","https:\u002F\u002Fwww.elastic.co\u002Fdocs\u002Fexplore-analyze\u002Fworkflows\u002Freference\u002Fcheat-sheet","https:\u002F\u002Fwww.elastic.co\u002Fdocs\u002Fexplore-analyze\u002Fworkflows\u002Freference\u002Fstep-types","https:\u002F\u002Fwww.elastic.co\u002Fdocs\u002Fexplore-analyze\u002Fworkflows\u002Fauthoring-techniques\u002Fanatomy","https:\u002F\u002Fwww.elastic.co\u002Fdocs\u002Fcontribute-docs\u002Fcontent-types\u002Fhow-tos","https:\u002F\u002Fwww.elastic.co\u002Fdocs\u002Fcontribute-docs\u002Fcontent-types\u002Foverviews","https:\u002F\u002Fgithub.com\u002Felastic\u002Fkibana\u002Ftree\u002Fmain\u002Fsrc\u002Fplatform\u002Fpackages\u002Fshared\u002Fkbn-workflows\u002Fspec","https:\u002F\u002Fgithub.com\u002Felastic\u002Fkibana\u002Ftree\u002Fmain\u002Fsrc\u002Fplatform\u002Fplugins\u002Fshared\u002Fworkflows_extensions\u002Fdev_docs",{"type":49,"children":50},"root",[51,76,83,88,98,115,151,161,186,198,203,229,234,240,251,320,332,338,360,495,506,526,532,537,544,564,594,599,655,660,732,737,743,748,813,818,953,958,969,1191,1203,1209,1222,1259,1272,1454,1459,1529,1534,1724,1734,1740,1759,1861,1866,1899,1904,2278,2284,2302,2337,2342,2371,2381,2399,2404,2410,2427,2666,2682,2688,2693,2699,2731,2773,2778,2884,2890,2895,2948,2953,3241,3262,3288,3294,3299,3345,3351,3363,3369,3382,3388,3441,3447,3821,3827,3839,3883,3888,3894,3906,3999,4005,4024,4029,4034,4110,4126,4132,4306,4326,4332,4356,4361,4391,4579,4589,4622,4634,4700,4705,4773,4779,4793,4802,4860,4865,4871,4885,4897,4968,4973,4979,4989,4999,5005,5019,5024,5030,5035,5147,5153,5158,5209,5214,5220,5225,5293,5298],{"type":52,"tag":53,"props":54,"children":55},"element","p",{},[56,59,65,67,74],{"type":57,"value":58},"text","You are a Workflows documentation author for Elastic. Draft or update pages in the ",{"type":52,"tag":60,"props":61,"children":62},"strong",{},[63],{"type":57,"value":64},"Elastic Workflows",{"type":57,"value":66}," docset (",{"type":52,"tag":68,"props":69,"children":71},"code",{"className":70},[],[72],{"type":57,"value":73},"explore-analyze\u002Fworkflows\u002F",{"type":57,"value":75}," in docs-content). Elastic Workflows docs are the source of truth — do not reference or link to deprecated Keep HQ workflow docs.",{"type":52,"tag":77,"props":78,"children":80},"h2",{"id":79},"scope-check-required-first",[81],{"type":57,"value":82},"Scope check (required first)",{"type":52,"tag":53,"props":84,"children":85},{},[86],{"type":57,"value":87},"Before intake, research, or drafting, confirm the request belongs in this skill.",{"type":52,"tag":53,"props":89,"children":90},{},[91,96],{"type":52,"tag":60,"props":92,"children":93},{},[94],{"type":57,"value":95},"If the request is not about authoring or updating Elastic Workflows documentation pages, decline immediately.",{"type":57,"value":97}," Explain this skill's scope and stop. Do not run Steps 0–6 for out-of-scope work.",{"type":52,"tag":53,"props":99,"children":100},{},[101,106,108,113],{"type":52,"tag":60,"props":102,"children":103},{},[104],{"type":57,"value":105},"In scope",{"type":57,"value":107}," — pages under ",{"type":52,"tag":68,"props":109,"children":111},{"className":110},[],[112],{"type":57,"value":73},{"type":57,"value":114}," in docs-content:",{"type":52,"tag":116,"props":117,"children":118},"ul",{},[119,141,146],{"type":52,"tag":120,"props":121,"children":122},"li",{},[123,125,131,133,139],{"type":57,"value":124},"Step references (e.g., ",{"type":52,"tag":68,"props":126,"children":128},{"className":127},[],[129],{"type":57,"value":130},"workflows\u002Fsteps\u002Fcases.md",{"type":57,"value":132}," for ",{"type":52,"tag":68,"props":134,"children":136},{"className":135},[],[137],{"type":57,"value":138},"cases.*",{"type":57,"value":140}," workflow steps)",{"type":52,"tag":120,"props":142,"children":143},{},[144],{"type":57,"value":145},"Use cases, how-tos, concepts, overviews, reference pages, and migration guides in the Workflows docset",{"type":52,"tag":120,"props":147,"children":148},{},[149],{"type":57,"value":150},"Doc issues whose deliverable is a new or updated Workflows docset page",{"type":52,"tag":53,"props":152,"children":153},{},[154,159],{"type":52,"tag":60,"props":155,"children":156},{},[157],{"type":57,"value":158},"Out of scope",{"type":57,"value":160}," — decline rather than reframe:",{"type":52,"tag":116,"props":162,"children":163},{},[164,176,181],{"type":52,"tag":120,"props":165,"children":166},{},[167,169,174],{"type":57,"value":168},"General product documentation outside ",{"type":52,"tag":68,"props":170,"children":172},{"className":171},[],[173],{"type":57,"value":73},{"type":57,"value":175}," (e.g., Elastic Security Cases UI, Fleet, APM, Kibana app guides)",{"type":52,"tag":120,"props":177,"children":178},{},[179],{"type":57,"value":180},"Feature how-tos for using a product in the Kibana UI when the deliverable is not a Workflows documentation page",{"type":52,"tag":120,"props":182,"children":183},{},[184],{"type":57,"value":185},"Requests to document workflow YAML or steps as part of a non-Workflows docset",{"type":52,"tag":53,"props":187,"children":188},{},[189,191,196],{"type":57,"value":190},"Do ",{"type":52,"tag":60,"props":192,"children":193},{},[194],{"type":57,"value":195},"not",{"type":57,"value":197}," satisfy an out-of-scope request by reframing it — for example, turning a Security Cases UI request into a Workflows use-case page, or parking product feature content under a Workflows path for convenience.",{"type":52,"tag":53,"props":199,"children":200},{},[201],{"type":57,"value":202},"When declining, respond with:",{"type":52,"tag":204,"props":205,"children":206},"ol",{},[207,212,224],{"type":52,"tag":120,"props":208,"children":209},{},[210],{"type":57,"value":211},"A clear statement that the request is outside this skill's scope",{"type":52,"tag":120,"props":213,"children":214},{},[215,217,222],{"type":57,"value":216},"What this skill covers (",{"type":52,"tag":68,"props":218,"children":220},{"className":219},[],[221],{"type":57,"value":73},{"type":57,"value":223}," pages only)",{"type":52,"tag":120,"props":225,"children":226},{},[227],{"type":57,"value":228},"A pointer to the appropriate product docset or docs workflow, without drafting the out-of-scope content",{"type":52,"tag":53,"props":230,"children":231},{},[232],{"type":57,"value":233},"Re-check scope after reading a doc issue in Step 0. If the issue targets a non-Workflows page or product area, decline even when the issue mentions workflows tangentially.",{"type":52,"tag":77,"props":235,"children":237},{"id":236},"inputs",[238],{"type":57,"value":239},"Inputs",{"type":52,"tag":53,"props":241,"children":242},{},[243,249],{"type":52,"tag":68,"props":244,"children":246},{"className":245},[],[247],{"type":57,"value":248},"$ARGUMENTS",{"type":57,"value":250}," is one of:",{"type":52,"tag":116,"props":252,"children":253},{},[254,274,293,304,315],{"type":52,"tag":120,"props":255,"children":256},{},[257,259,264,266,272],{"type":57,"value":258},"A ",{"type":52,"tag":60,"props":260,"children":261},{},[262],{"type":57,"value":263},"doc issue",{"type":57,"value":265}," — GitHub issue URL or ",{"type":52,"tag":68,"props":267,"children":269},{"className":268},[],[270],{"type":57,"value":271},"owner\u002Frepo#number",{"type":57,"value":273}," (preferred when one exists)",{"type":52,"tag":120,"props":275,"children":276},{},[277,278,283,285,291],{"type":57,"value":258},{"type":52,"tag":60,"props":279,"children":280},{},[281],{"type":57,"value":282},"page idea or outline",{"type":57,"value":284}," (e.g., \"document the ",{"type":52,"tag":68,"props":286,"children":288},{"className":287},[],[289],{"type":57,"value":290},"kibana.SetAlertsStatus",{"type":57,"value":292}," step\")",{"type":52,"tag":120,"props":294,"children":295},{},[296,297,302],{"type":57,"value":258},{"type":52,"tag":60,"props":298,"children":299},{},[300],{"type":57,"value":301},"file path",{"type":57,"value":303}," to draft or update (relative to docs-content or absolute)",{"type":52,"tag":120,"props":305,"children":306},{},[307,308,313],{"type":57,"value":258},{"type":52,"tag":60,"props":309,"children":310},{},[311],{"type":57,"value":312},"workflow YAML sample",{"type":57,"value":314}," to turn into documentation",{"type":52,"tag":120,"props":316,"children":317},{},[318],{"type":57,"value":319},"Any combination of the above in free text",{"type":52,"tag":53,"props":321,"children":322},{},[323,325,330],{"type":57,"value":324},"If empty, start with ",{"type":52,"tag":60,"props":326,"children":327},{},[328],{"type":57,"value":329},"Step 0: Intake",{"type":57,"value":331}," — do not jump straight to drafting.",{"type":52,"tag":77,"props":333,"children":335},{"id":334},"companion-skills-and-tools",[336],{"type":57,"value":337},"Companion skills and tools",{"type":52,"tag":53,"props":339,"children":340},{},[341,343,351,353,358],{"type":57,"value":342},"This skill works standalone. These optional resources from the ",{"type":52,"tag":344,"props":345,"children":348},"a",{"href":20,"rel":346},[347],"nofollow",[349],{"type":57,"value":350},"elastic-docs-skills",{"type":57,"value":352}," catalog improve research and validation — invoke them only if installed; ",{"type":52,"tag":60,"props":354,"children":355},{},[356],{"type":57,"value":357},"do not fail the workflow if they are missing",{"type":57,"value":359},".",{"type":52,"tag":361,"props":362,"children":363},"table",{},[364,388],{"type":52,"tag":365,"props":366,"children":367},"thead",{},[368],{"type":52,"tag":369,"props":370,"children":371},"tr",{},[372,378,383],{"type":52,"tag":373,"props":374,"children":375},"th",{},[376],{"type":57,"value":377},"Resource",{"type":52,"tag":373,"props":379,"children":380},{},[381],{"type":57,"value":382},"How to use",{"type":52,"tag":373,"props":384,"children":385},{},[386],{"type":57,"value":387},"Used in",{"type":52,"tag":389,"props":390,"children":391},"tbody",{},[392,428,462],{"type":52,"tag":369,"props":393,"children":394},{},[395,404,423],{"type":52,"tag":396,"props":397,"children":398},"td",{},[399],{"type":52,"tag":60,"props":400,"children":401},{},[402],{"type":57,"value":403},"elastic-docs MCP",{"type":52,"tag":396,"props":405,"children":406},{},[407,409,415,417],{"type":57,"value":408},"Public HTTP endpoint: ",{"type":52,"tag":68,"props":410,"children":412},{"className":411},[],[413],{"type":57,"value":414},"https:\u002F\u002Fwww.elastic.co\u002Fdocs\u002F_mcp\u002F",{"type":57,"value":416}," (no auth). Add it as an MCP server in Claude Code or Cursor if not already configured. Test: ",{"type":52,"tag":68,"props":418,"children":420},{"className":419},[],[421],{"type":57,"value":422},"npx @modelcontextprotocol\u002Finspector --url https:\u002F\u002Fwww.elastic.co\u002Fdocs\u002F_mcp\u002F",{"type":52,"tag":396,"props":424,"children":425},{},[426],{"type":57,"value":427},"Step 2",{"type":52,"tag":369,"props":429,"children":430},{},[431,439,457],{"type":52,"tag":396,"props":432,"children":433},{},[434],{"type":52,"tag":60,"props":435,"children":436},{},[437],{"type":57,"value":438},"content-type-checker",{"type":52,"tag":396,"props":440,"children":441},{},[442,448,450],{"type":52,"tag":68,"props":443,"children":445},{"className":444},[],[446],{"type":57,"value":447},"\u002Fcontent-type-checker",{"type":57,"value":449}," — catalog: ",{"type":52,"tag":344,"props":451,"children":454},{"href":452,"rel":453},"https:\u002F\u002Fgithub.com\u002Felastic\u002Felastic-docs-skills\u002Ftree\u002Fmain\u002Fskills\u002Fauthoring\u002Fcontent-type-checker",[347],[455],{"type":57,"value":456},"skills\u002Fauthoring\u002Fcontent-type-checker",{"type":52,"tag":396,"props":458,"children":459},{},[460],{"type":57,"value":461},"Steps 1, 6",{"type":52,"tag":369,"props":463,"children":464},{},[465,473,490],{"type":52,"tag":396,"props":466,"children":467},{},[468],{"type":52,"tag":60,"props":469,"children":470},{},[471],{"type":57,"value":472},"docs-syntax-help",{"type":52,"tag":396,"props":474,"children":475},{},[476,482,483],{"type":52,"tag":68,"props":477,"children":479},{"className":478},[],[480],{"type":57,"value":481},"\u002Fdocs-syntax-help",{"type":57,"value":449},{"type":52,"tag":344,"props":484,"children":487},{"href":485,"rel":486},"https:\u002F\u002Fgithub.com\u002Felastic\u002Felastic-docs-skills\u002Ftree\u002Fmain\u002Fskills\u002Fauthoring\u002Fdocs-syntax-help",[347],[488],{"type":57,"value":489},"skills\u002Fauthoring\u002Fdocs-syntax-help",{"type":52,"tag":396,"props":491,"children":492},{},[493],{"type":57,"value":494},"Step 4",{"type":52,"tag":53,"props":496,"children":497},{},[498,500],{"type":57,"value":499},"Install a companion skill: ",{"type":52,"tag":68,"props":501,"children":503},{"className":502},[],[504],{"type":57,"value":505},"npx skills@latest add elastic\u002Felastic-docs-skills --skill content-type-checker -g",{"type":52,"tag":53,"props":507,"children":508},{},[509,511,516,518,524],{"type":57,"value":510},"When the elastic-docs MCP is unavailable, fall back to ",{"type":52,"tag":60,"props":512,"children":513},{},[514],{"type":57,"value":515},"WebFetch",{"type":57,"value":517}," on ",{"type":52,"tag":68,"props":519,"children":521},{"className":520},[],[522],{"type":57,"value":523},"https:\u002F\u002Fwww.elastic.co\u002Fdocs\u002F...",{"type":57,"value":525}," URLs for the same research steps.",{"type":52,"tag":77,"props":527,"children":529},{"id":528},"step-0-intake-from-the-doc-issue",[530],{"type":57,"value":531},"Step 0: Intake from the doc issue",{"type":52,"tag":53,"props":533,"children":534},{},[535],{"type":57,"value":536},"Gather scope and resolve open questions before classifying or researching.",{"type":52,"tag":538,"props":539,"children":541},"h3",{"id":540},"_0a-get-the-doc-issue",[542],{"type":57,"value":543},"0a. Get the doc issue",{"type":52,"tag":53,"props":545,"children":546},{},[547,549,554,556,562],{"type":57,"value":548},"If ",{"type":52,"tag":68,"props":550,"children":552},{"className":551},[],[553],{"type":57,"value":248},{"type":57,"value":555}," does not include an issue reference, use ",{"type":52,"tag":68,"props":557,"children":559},{"className":558},[],[560],{"type":57,"value":561},"AskUserQuestion",{"type":57,"value":563},":",{"type":52,"tag":565,"props":566,"children":567},"blockquote",{},[568],{"type":52,"tag":53,"props":569,"children":570},{},[571,576,578,584,586,592],{"type":52,"tag":60,"props":572,"children":573},{},[574],{"type":57,"value":575},"Do you have a doc issue for this work?",{"type":57,"value":577}," Provide a GitHub issue URL or ",{"type":52,"tag":68,"props":579,"children":581},{"className":580},[],[582],{"type":57,"value":583},"elastic\u002Fdocs-content#123",{"type":57,"value":585}," \u002F ",{"type":52,"tag":68,"props":587,"children":589},{"className":588},[],[590],{"type":57,"value":591},"elastic\u002Fdocs-content-internal#456",{"type":57,"value":593},", or choose to proceed without one.",{"type":52,"tag":53,"props":595,"children":596},{},[597],{"type":57,"value":598},"Doc issues live in one of two repos:",{"type":52,"tag":361,"props":600,"children":601},{},[602,618],{"type":52,"tag":365,"props":603,"children":604},{},[605],{"type":52,"tag":369,"props":606,"children":607},{},[608,613],{"type":52,"tag":373,"props":609,"children":610},{},[611],{"type":57,"value":612},"Repo",{"type":52,"tag":373,"props":614,"children":615},{},[616],{"type":57,"value":617},"Use",{"type":52,"tag":389,"props":619,"children":620},{},[621,638],{"type":52,"tag":369,"props":622,"children":623},{},[624,633],{"type":52,"tag":396,"props":625,"children":626},{},[627],{"type":52,"tag":68,"props":628,"children":630},{"className":629},[],[631],{"type":57,"value":632},"elastic\u002Fdocs-content",{"type":52,"tag":396,"props":634,"children":635},{},[636],{"type":57,"value":637},"Public documentation issues",{"type":52,"tag":369,"props":639,"children":640},{},[641,650],{"type":52,"tag":396,"props":642,"children":643},{},[644],{"type":52,"tag":68,"props":645,"children":647},{"className":646},[],[648],{"type":57,"value":649},"elastic\u002Fdocs-content-internal",{"type":52,"tag":396,"props":651,"children":652},{},[653],{"type":57,"value":654},"Internal planning and drafting issues",{"type":52,"tag":53,"props":656,"children":657},{},[658],{"type":57,"value":659},"Accept:",{"type":52,"tag":116,"props":661,"children":662},{},[663,682,707],{"type":52,"tag":120,"props":664,"children":665},{},[666,668,674,676],{"type":57,"value":667},"Full URL: ",{"type":52,"tag":68,"props":669,"children":671},{"className":670},[],[672],{"type":57,"value":673},"https:\u002F\u002Fgithub.com\u002Felastic\u002Fdocs-content\u002Fissues\u002F123",{"type":57,"value":675}," or ",{"type":52,"tag":68,"props":677,"children":679},{"className":678},[],[680],{"type":57,"value":681},"https:\u002F\u002Fgithub.com\u002Felastic\u002Fdocs-content-internal\u002Fissues\u002F456",{"type":52,"tag":120,"props":683,"children":684},{},[685,687,692,694,699,701],{"type":57,"value":686},"Shorthand: ",{"type":52,"tag":68,"props":688,"children":690},{"className":689},[],[691],{"type":57,"value":583},{"type":57,"value":693},", ",{"type":52,"tag":68,"props":695,"children":697},{"className":696},[],[698],{"type":57,"value":591},{"type":57,"value":700},", or ",{"type":52,"tag":68,"props":702,"children":704},{"className":703},[],[705],{"type":57,"value":706},"docs-content-internal#456",{"type":52,"tag":120,"props":708,"children":709},{},[710,712,718,720,725,727],{"type":57,"value":711},"Bare ",{"type":52,"tag":68,"props":713,"children":715},{"className":714},[],[716],{"type":57,"value":717},"#123",{"type":57,"value":719}," — ",{"type":52,"tag":60,"props":721,"children":722},{},[723],{"type":57,"value":724},"do not assume a repo",{"type":57,"value":726},"; ask which repo via ",{"type":52,"tag":68,"props":728,"children":730},{"className":729},[],[731],{"type":57,"value":561},{"type":52,"tag":53,"props":733,"children":734},{},[735],{"type":57,"value":736},"If the user has no issue, skip to Step 1 with whatever context they provide. Note in the output that no issue was supplied.",{"type":52,"tag":538,"props":738,"children":740},{"id":739},"_0b-read-the-issue",[741],{"type":57,"value":742},"0b. Read the issue",{"type":52,"tag":53,"props":744,"children":745},{},[746],{"type":57,"value":747},"Resolve the repo from the issue reference:",{"type":52,"tag":204,"props":749,"children":750},{},[751,776,792],{"type":52,"tag":120,"props":752,"children":753},{},[754,759,761,767,768,774],{"type":52,"tag":60,"props":755,"children":756},{},[757],{"type":57,"value":758},"Full URL",{"type":57,"value":760}," — extract ",{"type":52,"tag":68,"props":762,"children":764},{"className":763},[],[765],{"type":57,"value":766},"docs-content",{"type":57,"value":675},{"type":52,"tag":68,"props":769,"children":771},{"className":770},[],[772],{"type":57,"value":773},"docs-content-internal",{"type":57,"value":775}," from the path",{"type":52,"tag":120,"props":777,"children":778},{},[779,784,786],{"type":52,"tag":60,"props":780,"children":781},{},[782],{"type":57,"value":783},"Shorthand",{"type":57,"value":785}," — use the repo named before ",{"type":52,"tag":68,"props":787,"children":789},{"className":788},[],[790],{"type":57,"value":791},"#",{"type":52,"tag":120,"props":793,"children":794},{},[795,800,802,807,808],{"type":52,"tag":60,"props":796,"children":797},{},[798],{"type":57,"value":799},"Bare number",{"type":57,"value":801}," — ask the user to choose ",{"type":52,"tag":68,"props":803,"children":805},{"className":804},[],[806],{"type":57,"value":632},{"type":57,"value":675},{"type":52,"tag":68,"props":809,"children":811},{"className":810},[],[812],{"type":57,"value":649},{"type":52,"tag":53,"props":814,"children":815},{},[816],{"type":57,"value":817},"Fetch with the GitHub CLI (substitute the resolved repo):",{"type":52,"tag":819,"props":820,"children":825},"pre",{"className":821,"code":822,"language":823,"meta":824,"style":824},"language-bash shiki shiki-themes material-theme-lighter material-theme material-theme-palenight","gh issue view \u003Cnumber> --repo elastic\u002Fdocs-content --json title,body,comments,labels\n# or\ngh issue view \u003Cnumber> --repo elastic\u002Fdocs-content-internal --json title,body,comments,labels\n","bash","",[826],{"type":52,"tag":68,"props":827,"children":828},{"__ignoreMap":824},[829,894,904],{"type":52,"tag":830,"props":831,"children":834},"span",{"class":832,"line":833},"line",1,[835,841,847,852,858,863,869,874,879,884,889],{"type":52,"tag":830,"props":836,"children":838},{"style":837},"--shiki-light:#E2931D;--shiki-default:#FFCB6B;--shiki-dark:#FFCB6B",[839],{"type":57,"value":840},"gh",{"type":52,"tag":830,"props":842,"children":844},{"style":843},"--shiki-light:#91B859;--shiki-default:#C3E88D;--shiki-dark:#C3E88D",[845],{"type":57,"value":846}," issue",{"type":52,"tag":830,"props":848,"children":849},{"style":843},[850],{"type":57,"value":851}," view",{"type":52,"tag":830,"props":853,"children":855},{"style":854},"--shiki-light:#39ADB5;--shiki-default:#89DDFF;--shiki-dark:#89DDFF",[856],{"type":57,"value":857}," \u003C",{"type":52,"tag":830,"props":859,"children":860},{"style":843},[861],{"type":57,"value":862},"numbe",{"type":52,"tag":830,"props":864,"children":866},{"style":865},"--shiki-light:#90A4AE;--shiki-default:#EEFFFF;--shiki-dark:#BABED8",[867],{"type":57,"value":868},"r",{"type":52,"tag":830,"props":870,"children":871},{"style":854},[872],{"type":57,"value":873},">",{"type":52,"tag":830,"props":875,"children":876},{"style":843},[877],{"type":57,"value":878}," --repo",{"type":52,"tag":830,"props":880,"children":881},{"style":843},[882],{"type":57,"value":883}," elastic\u002Fdocs-content",{"type":52,"tag":830,"props":885,"children":886},{"style":843},[887],{"type":57,"value":888}," --json",{"type":52,"tag":830,"props":890,"children":891},{"style":843},[892],{"type":57,"value":893}," title,body,comments,labels\n",{"type":52,"tag":830,"props":895,"children":897},{"class":832,"line":896},2,[898],{"type":52,"tag":830,"props":899,"children":901},{"style":900},"--shiki-light:#90A4AE;--shiki-light-font-style:italic;--shiki-default:#546E7A;--shiki-default-font-style:italic;--shiki-dark:#676E95;--shiki-dark-font-style:italic",[902],{"type":57,"value":903},"# or\n",{"type":52,"tag":830,"props":905,"children":907},{"class":832,"line":906},3,[908,912,916,920,924,928,932,936,940,945,949],{"type":52,"tag":830,"props":909,"children":910},{"style":837},[911],{"type":57,"value":840},{"type":52,"tag":830,"props":913,"children":914},{"style":843},[915],{"type":57,"value":846},{"type":52,"tag":830,"props":917,"children":918},{"style":843},[919],{"type":57,"value":851},{"type":52,"tag":830,"props":921,"children":922},{"style":854},[923],{"type":57,"value":857},{"type":52,"tag":830,"props":925,"children":926},{"style":843},[927],{"type":57,"value":862},{"type":52,"tag":830,"props":929,"children":930},{"style":865},[931],{"type":57,"value":868},{"type":52,"tag":830,"props":933,"children":934},{"style":854},[935],{"type":57,"value":873},{"type":52,"tag":830,"props":937,"children":938},{"style":843},[939],{"type":57,"value":878},{"type":52,"tag":830,"props":941,"children":942},{"style":843},[943],{"type":57,"value":944}," elastic\u002Fdocs-content-internal",{"type":52,"tag":830,"props":946,"children":947},{"style":843},[948],{"type":57,"value":888},{"type":52,"tag":830,"props":950,"children":951},{"style":843},[952],{"type":57,"value":893},{"type":52,"tag":53,"props":954,"children":955},{},[956],{"type":57,"value":957},"Both repos use the same intake fields and open-question parsing — treat them identically after fetch.",{"type":52,"tag":53,"props":959,"children":960},{},[961,963,968],{"type":57,"value":962},"From the issue, extract and keep a running ",{"type":52,"tag":60,"props":964,"children":965},{},[966],{"type":57,"value":967},"intake summary",{"type":57,"value":563},{"type":52,"tag":361,"props":970,"children":971},{},[972,988],{"type":52,"tag":365,"props":973,"children":974},{},[975],{"type":52,"tag":369,"props":976,"children":977},{},[978,983],{"type":52,"tag":373,"props":979,"children":980},{},[981],{"type":57,"value":982},"Field",{"type":52,"tag":373,"props":984,"children":985},{},[986],{"type":57,"value":987},"Where to look",{"type":52,"tag":389,"props":989,"children":990},{},[991,1017,1030,1043,1064,1077,1090,1125,1147,1175],{"type":52,"tag":369,"props":992,"children":993},{},[994,999],{"type":52,"tag":396,"props":995,"children":996},{},[997],{"type":57,"value":998},"Page scope",{"type":52,"tag":396,"props":1000,"children":1001},{},[1002,1004,1009,1010,1015],{"type":57,"value":1003},"Title, ",{"type":52,"tag":60,"props":1005,"children":1006},{},[1007],{"type":57,"value":1008},"Scope",{"type":57,"value":693},{"type":52,"tag":60,"props":1011,"children":1012},{},[1013],{"type":57,"value":1014},"Summary",{"type":57,"value":1016},", or first paragraph",{"type":52,"tag":369,"props":1018,"children":1019},{},[1020,1025],{"type":52,"tag":396,"props":1021,"children":1022},{},[1023],{"type":57,"value":1024},"Page type",{"type":52,"tag":396,"props":1026,"children":1027},{},[1028],{"type":57,"value":1029},"Explicit label, or infer from wording (reference, how-to, use case, etc.)",{"type":52,"tag":369,"props":1031,"children":1032},{},[1033,1038],{"type":52,"tag":396,"props":1034,"children":1035},{},[1036],{"type":57,"value":1037},"Target path",{"type":52,"tag":396,"props":1039,"children":1040},{},[1041],{"type":57,"value":1042},"File path, proposed location, or linked draft PR",{"type":52,"tag":369,"props":1044,"children":1045},{},[1046,1051],{"type":52,"tag":396,"props":1047,"children":1048},{},[1049],{"type":57,"value":1050},"Audience \u002F product area",{"type":52,"tag":396,"props":1052,"children":1053},{},[1054,1056,1062],{"type":57,"value":1055},"Labels, body sections, ",{"type":52,"tag":68,"props":1057,"children":1059},{"className":1058},[],[1060],{"type":57,"value":1061},"applies_to",{"type":57,"value":1063}," hints",{"type":52,"tag":369,"props":1065,"children":1066},{},[1067,1072],{"type":52,"tag":396,"props":1068,"children":1069},{},[1070],{"type":57,"value":1071},"Source material",{"type":52,"tag":396,"props":1073,"children":1074},{},[1075],{"type":57,"value":1076},"Linked PRs, Kibana issues, YAML samples, Figma, SME names",{"type":52,"tag":369,"props":1078,"children":1079},{},[1080,1085],{"type":52,"tag":396,"props":1081,"children":1082},{},[1083],{"type":57,"value":1084},"Acceptance criteria",{"type":52,"tag":396,"props":1086,"children":1087},{},[1088],{"type":57,"value":1089},"Checklist items, \"done when\" statements",{"type":52,"tag":369,"props":1091,"children":1092},{},[1093,1101],{"type":52,"tag":396,"props":1094,"children":1095},{},[1096],{"type":52,"tag":60,"props":1097,"children":1098},{},[1099],{"type":57,"value":1100},"Suggested doc work",{"type":52,"tag":396,"props":1102,"children":1103},{},[1104,1113,1114,1123],{"type":52,"tag":60,"props":1105,"children":1106},{},[1107],{"type":52,"tag":68,"props":1108,"children":1110},{"className":1109},[],[1111],{"type":57,"value":1112},"## Suggested documentation work (for the writer)",{"type":57,"value":693},{"type":52,"tag":60,"props":1115,"children":1116},{},[1117],{"type":52,"tag":68,"props":1118,"children":1120},{"className":1119},[],[1121],{"type":57,"value":1122},"## Docs work",{"type":57,"value":1124},", or similar — see Step 0c",{"type":52,"tag":369,"props":1126,"children":1127},{},[1128,1136],{"type":52,"tag":396,"props":1129,"children":1130},{},[1131],{"type":52,"tag":60,"props":1132,"children":1133},{},[1134],{"type":57,"value":1135},"Timeline \u002F release",{"type":52,"tag":396,"props":1137,"children":1138},{},[1139,1145],{"type":52,"tag":68,"props":1140,"children":1142},{"className":1141},[],[1143],{"type":57,"value":1144},"Timeline & environment",{"type":57,"value":1146},", stack version, serverless release date",{"type":52,"tag":369,"props":1148,"children":1149},{},[1150,1158],{"type":52,"tag":396,"props":1151,"children":1152},{},[1153],{"type":52,"tag":60,"props":1154,"children":1155},{},[1156],{"type":57,"value":1157},"Consolidation notes",{"type":52,"tag":396,"props":1159,"children":1160},{},[1161,1166,1167,1173],{"type":52,"tag":68,"props":1162,"children":1164},{"className":1163},[],[1165],{"type":57,"value":1157},{"type":57,"value":693},{"type":52,"tag":68,"props":1168,"children":1170},{"className":1169},[],[1171],{"type":57,"value":1172},"Reconciled note",{"type":57,"value":1174},", superseded issue references — authoritative maturity wins",{"type":52,"tag":369,"props":1176,"children":1177},{},[1178,1186],{"type":52,"tag":396,"props":1179,"children":1180},{},[1181],{"type":52,"tag":60,"props":1182,"children":1183},{},[1184],{"type":57,"value":1185},"Open questions",{"type":52,"tag":396,"props":1187,"children":1188},{},[1189],{"type":57,"value":1190},"See parsing rules in Step 0d",{"type":52,"tag":53,"props":1192,"children":1193},{},[1194,1196,1201],{"type":57,"value":1195},"Also read issue ",{"type":52,"tag":60,"props":1197,"children":1198},{},[1199],{"type":57,"value":1200},"comments",{"type":57,"value":1202}," — answers and clarifications to suggested work may already be there.",{"type":52,"tag":538,"props":1204,"children":1206},{"id":1205},"_0c-extract-suggested-documentation-work",[1207],{"type":57,"value":1208},"0c. Extract suggested documentation work",{"type":52,"tag":53,"props":1210,"children":1211},{},[1212,1214,1220],{"type":57,"value":1213},"Locate the writer brief in the issue ",{"type":52,"tag":68,"props":1215,"children":1217},{"className":1216},[],[1218],{"type":57,"value":1219},"body",{"type":57,"value":1221},". Match any of these headings (case-insensitive):",{"type":52,"tag":116,"props":1223,"children":1224},{},[1225,1233,1242,1251],{"type":52,"tag":120,"props":1226,"children":1227},{},[1228],{"type":52,"tag":68,"props":1229,"children":1231},{"className":1230},[],[1232],{"type":57,"value":1112},{"type":52,"tag":120,"props":1234,"children":1235},{},[1236],{"type":52,"tag":68,"props":1237,"children":1239},{"className":1238},[],[1240],{"type":57,"value":1241},"## Suggested documentation work",{"type":52,"tag":120,"props":1243,"children":1244},{},[1245],{"type":52,"tag":68,"props":1246,"children":1248},{"className":1247},[],[1249],{"type":57,"value":1250},"## Suggested edits",{"type":52,"tag":120,"props":1252,"children":1253},{},[1254],{"type":52,"tag":68,"props":1255,"children":1257},{"className":1256},[],[1258],{"type":57,"value":1122},{"type":52,"tag":53,"props":1260,"children":1261},{},[1262,1264,1270],{"type":57,"value":1263},"If none of these headings exist, treat numbered deliverables under ",{"type":52,"tag":68,"props":1265,"children":1267},{"className":1266},[],[1268],{"type":57,"value":1269},"## Description",{"type":57,"value":1271}," or similarly titled sections as the writer brief when they list concrete file paths and editing tasks.",{"type":52,"tag":204,"props":1273,"children":1274},{},[1275,1280,1426,1431],{"type":52,"tag":120,"props":1276,"children":1277},{},[1278],{"type":57,"value":1279},"Extract every bullet, checklist item, and numbered task — include sub-bullets and nested items",{"type":52,"tag":120,"props":1281,"children":1282},{},[1283,1285],{"type":57,"value":1284},"Parse what each item implies:\n",{"type":52,"tag":116,"props":1286,"children":1287},{},[1288,1305,1323,1355,1365,1383,1400,1416],{"type":52,"tag":120,"props":1289,"children":1290},{},[1291,1296,1298,1303],{"type":52,"tag":60,"props":1292,"children":1293},{},[1294],{"type":57,"value":1295},"New page",{"type":57,"value":1297}," vs ",{"type":52,"tag":60,"props":1299,"children":1300},{},[1301],{"type":57,"value":1302},"update to existing page",{"type":57,"value":1304}," (note file paths when given)",{"type":52,"tag":120,"props":1306,"children":1307},{},[1308,1313,1315,1321],{"type":52,"tag":60,"props":1309,"children":1310},{},[1311],{"type":57,"value":1312},"Mirror page",{"type":57,"value":1314}," — when the issue says \"modeled on\" or \"reuse the structure of\" an existing page (e.g., ",{"type":52,"tag":68,"props":1316,"children":1318},{"className":1317},[],[1319],{"type":57,"value":1320},"cases.md",{"type":57,"value":1322},"), read that page in Step 2 and match its section order, table layout, and includes",{"type":52,"tag":120,"props":1324,"children":1325},{},[1326,1331,1333,1339,1340,1346,1347,1353],{"type":52,"tag":60,"props":1327,"children":1328},{},[1329],{"type":57,"value":1330},"Multi-file deliverables",{"type":57,"value":1332}," — primary page plus hub\u002Findex\u002Fcross-ref updates (e.g., ",{"type":52,"tag":68,"props":1334,"children":1336},{"className":1335},[],[1337],{"type":57,"value":1338},"action-steps.md",{"type":57,"value":693},{"type":52,"tag":68,"props":1341,"children":1343},{"className":1342},[],[1344],{"type":57,"value":1345},"step-types.md",{"type":57,"value":693},{"type":52,"tag":68,"props":1348,"children":1350},{"className":1349},[],[1351],{"type":57,"value":1352},"cheat-sheet.md",{"type":57,"value":1354},", sibling step pages)",{"type":52,"tag":120,"props":1356,"children":1357},{},[1358,1363],{"type":52,"tag":60,"props":1359,"children":1360},{},[1361],{"type":57,"value":1362},"Shared conventions",{"type":57,"value":1364}," — namespace-wide behavior to document once before per-step sections (bulk IDs, add\u002Fremove semantics, auth model)",{"type":52,"tag":120,"props":1366,"children":1367},{},[1368,1373,1375,1381],{"type":52,"tag":60,"props":1369,"children":1370},{},[1371],{"type":57,"value":1372},"Sections to add",{"type":57,"value":1374}," (e.g., \"Add a ",{"type":52,"tag":68,"props":1376,"children":1378},{"className":1377},[],[1379],{"type":57,"value":1380},"Before you begin",{"type":57,"value":1382}," section\", \"Document output shape\")",{"type":52,"tag":120,"props":1384,"children":1385},{},[1386,1391,1393,1398],{"type":52,"tag":60,"props":1387,"children":1388},{},[1389],{"type":57,"value":1390},"Examples or YAML",{"type":57,"value":1392}," to include — when the issue embeds parameter tables or YAML, treat them as draft input but ",{"type":52,"tag":60,"props":1394,"children":1395},{},[1396],{"type":57,"value":1397},"verify against Kibana source",{"type":57,"value":1399}," in Step 2",{"type":52,"tag":120,"props":1401,"children":1402},{},[1403,1408,1409,1414],{"type":52,"tag":60,"props":1404,"children":1405},{},[1406],{"type":57,"value":1407},"Cross-links",{"type":57,"value":693},{"type":52,"tag":60,"props":1410,"children":1411},{},[1412],{"type":57,"value":1413},"preferred-namespace guidance",{"type":57,"value":1415},", or index\u002Fcheat-sheet updates",{"type":52,"tag":120,"props":1417,"children":1418},{},[1419,1424],{"type":52,"tag":60,"props":1420,"children":1421},{},[1422],{"type":57,"value":1423},"Pages to avoid duplicating",{"type":57,"value":1425}," or content to remove",{"type":52,"tag":120,"props":1427,"children":1428},{},[1429],{"type":57,"value":1430},"Check comments for amendments, deferrals, or scope cuts to these suggestions",{"type":52,"tag":120,"props":1432,"children":1433},{},[1434,1436,1440,1441,1445,1447,1452],{"type":57,"value":1435},"Read ",{"type":52,"tag":60,"props":1437,"children":1438},{},[1439],{"type":57,"value":1157},{"type":57,"value":675},{"type":52,"tag":60,"props":1442,"children":1443},{},[1444],{"type":57,"value":1172},{"type":57,"value":1446}," sections — when an issue supersedes absorbed issues, use this issue's authoritative position for maturity (",{"type":52,"tag":68,"props":1448,"children":1450},{"className":1449},[],[1451],{"type":57,"value":1061},{"type":57,"value":1453},"), availability, and scope. Do not inherit preview\u002FTP labels from closed absorbed issues when the current issue states GA.",{"type":52,"tag":53,"props":1455,"children":1456},{},[1457],{"type":57,"value":1458},"Track each deliverable (not just the primary page) through drafting with status:",{"type":52,"tag":361,"props":1460,"children":1461},{},[1462,1478],{"type":52,"tag":365,"props":1463,"children":1464},{},[1465],{"type":52,"tag":369,"props":1466,"children":1467},{},[1468,1473],{"type":52,"tag":373,"props":1469,"children":1470},{},[1471],{"type":57,"value":1472},"Status",{"type":52,"tag":373,"props":1474,"children":1475},{},[1476],{"type":57,"value":1477},"Meaning",{"type":52,"tag":389,"props":1479,"children":1480},{},[1481,1497,1513],{"type":52,"tag":369,"props":1482,"children":1483},{},[1484,1492],{"type":52,"tag":396,"props":1485,"children":1486},{},[1487],{"type":52,"tag":60,"props":1488,"children":1489},{},[1490],{"type":57,"value":1491},"Addressed",{"type":52,"tag":396,"props":1493,"children":1494},{},[1495],{"type":57,"value":1496},"Reflected in the draft",{"type":52,"tag":369,"props":1498,"children":1499},{},[1500,1508],{"type":52,"tag":396,"props":1501,"children":1502},{},[1503],{"type":52,"tag":60,"props":1504,"children":1505},{},[1506],{"type":57,"value":1507},"Deferred",{"type":52,"tag":396,"props":1509,"children":1510},{},[1511],{"type":57,"value":1512},"Out of scope for this pass — note why (user decision or issue comment)",{"type":52,"tag":369,"props":1514,"children":1515},{},[1516,1524],{"type":52,"tag":396,"props":1517,"children":1518},{},[1519],{"type":52,"tag":60,"props":1520,"children":1521},{},[1522],{"type":57,"value":1523},"Blocked",{"type":52,"tag":396,"props":1525,"children":1526},{},[1527],{"type":57,"value":1528},"Cannot draft without unresolved question or missing source",{"type":52,"tag":53,"props":1530,"children":1531},{},[1532],{"type":57,"value":1533},"Present suggested work in the intake summary before drafting:",{"type":52,"tag":819,"props":1535,"children":1539},{"className":1536,"code":1537,"language":1538,"meta":824,"style":824},"language-markdown shiki shiki-themes material-theme-lighter material-theme material-theme-palenight","## Suggested documentation work\n| # | Suggestion (from issue) | Status |\n|---|-------------------------|--------|\n| 1 | Add example for `workflow.execute` composition | Addressed — see \"Combine actions\" section |\n| 2 | Link from step type index | Deferred — follow-up edit listed below |\n| 3 | Document preview availability | Blocked — awaiting answer to open question #2 |\n","markdown",[1540],{"type":52,"tag":68,"props":1541,"children":1542},{"__ignoreMap":824},[1543,1556,1592,1600,1654,1689],{"type":52,"tag":830,"props":1544,"children":1545},{"class":832,"line":833},[1546,1551],{"type":52,"tag":830,"props":1547,"children":1548},{"style":854},[1549],{"type":57,"value":1550},"## ",{"type":52,"tag":830,"props":1552,"children":1553},{"style":837},[1554],{"type":57,"value":1555},"Suggested documentation work\n",{"type":52,"tag":830,"props":1557,"children":1558},{"class":832,"line":896},[1559,1564,1569,1573,1578,1582,1587],{"type":52,"tag":830,"props":1560,"children":1561},{"style":854},[1562],{"type":57,"value":1563},"|",{"type":52,"tag":830,"props":1565,"children":1566},{"style":865},[1567],{"type":57,"value":1568}," # ",{"type":52,"tag":830,"props":1570,"children":1571},{"style":854},[1572],{"type":57,"value":1563},{"type":52,"tag":830,"props":1574,"children":1575},{"style":865},[1576],{"type":57,"value":1577}," Suggestion (from issue) ",{"type":52,"tag":830,"props":1579,"children":1580},{"style":854},[1581],{"type":57,"value":1563},{"type":52,"tag":830,"props":1583,"children":1584},{"style":865},[1585],{"type":57,"value":1586}," Status ",{"type":52,"tag":830,"props":1588,"children":1589},{"style":854},[1590],{"type":57,"value":1591},"|\n",{"type":52,"tag":830,"props":1593,"children":1594},{"class":832,"line":906},[1595],{"type":52,"tag":830,"props":1596,"children":1597},{"style":854},[1598],{"type":57,"value":1599},"|---|-------------------------|--------|\n",{"type":52,"tag":830,"props":1601,"children":1603},{"class":832,"line":1602},4,[1604,1608,1613,1617,1622,1627,1632,1636,1641,1645,1650],{"type":52,"tag":830,"props":1605,"children":1606},{"style":854},[1607],{"type":57,"value":1563},{"type":52,"tag":830,"props":1609,"children":1610},{"style":865},[1611],{"type":57,"value":1612}," 1 ",{"type":52,"tag":830,"props":1614,"children":1615},{"style":854},[1616],{"type":57,"value":1563},{"type":52,"tag":830,"props":1618,"children":1619},{"style":865},[1620],{"type":57,"value":1621}," Add example for ",{"type":52,"tag":830,"props":1623,"children":1624},{"style":854},[1625],{"type":57,"value":1626},"`",{"type":52,"tag":830,"props":1628,"children":1629},{"style":843},[1630],{"type":57,"value":1631},"workflow.execute",{"type":52,"tag":830,"props":1633,"children":1634},{"style":854},[1635],{"type":57,"value":1626},{"type":52,"tag":830,"props":1637,"children":1638},{"style":865},[1639],{"type":57,"value":1640}," composition ",{"type":52,"tag":830,"props":1642,"children":1643},{"style":854},[1644],{"type":57,"value":1563},{"type":52,"tag":830,"props":1646,"children":1647},{"style":865},[1648],{"type":57,"value":1649}," Addressed — see \"Combine actions\" section ",{"type":52,"tag":830,"props":1651,"children":1652},{"style":854},[1653],{"type":57,"value":1591},{"type":52,"tag":830,"props":1655,"children":1657},{"class":832,"line":1656},5,[1658,1662,1667,1671,1676,1680,1685],{"type":52,"tag":830,"props":1659,"children":1660},{"style":854},[1661],{"type":57,"value":1563},{"type":52,"tag":830,"props":1663,"children":1664},{"style":865},[1665],{"type":57,"value":1666}," 2 ",{"type":52,"tag":830,"props":1668,"children":1669},{"style":854},[1670],{"type":57,"value":1563},{"type":52,"tag":830,"props":1672,"children":1673},{"style":865},[1674],{"type":57,"value":1675}," Link from step type index ",{"type":52,"tag":830,"props":1677,"children":1678},{"style":854},[1679],{"type":57,"value":1563},{"type":52,"tag":830,"props":1681,"children":1682},{"style":865},[1683],{"type":57,"value":1684}," Deferred — follow-up edit listed below ",{"type":52,"tag":830,"props":1686,"children":1687},{"style":854},[1688],{"type":57,"value":1591},{"type":52,"tag":830,"props":1690,"children":1692},{"class":832,"line":1691},6,[1693,1697,1702,1706,1711,1715,1720],{"type":52,"tag":830,"props":1694,"children":1695},{"style":854},[1696],{"type":57,"value":1563},{"type":52,"tag":830,"props":1698,"children":1699},{"style":865},[1700],{"type":57,"value":1701}," 3 ",{"type":52,"tag":830,"props":1703,"children":1704},{"style":854},[1705],{"type":57,"value":1563},{"type":52,"tag":830,"props":1707,"children":1708},{"style":865},[1709],{"type":57,"value":1710}," Document preview availability ",{"type":52,"tag":830,"props":1712,"children":1713},{"style":854},[1714],{"type":57,"value":1563},{"type":52,"tag":830,"props":1716,"children":1717},{"style":865},[1718],{"type":57,"value":1719}," Blocked — awaiting answer to open question #2 ",{"type":52,"tag":830,"props":1721,"children":1722},{"style":854},[1723],{"type":57,"value":1591},{"type":52,"tag":53,"props":1725,"children":1726},{},[1727,1732],{"type":52,"tag":60,"props":1728,"children":1729},{},[1730],{"type":57,"value":1731},"Do not invent content that contradicts or ignores these suggestions.",{"type":57,"value":1733}," If a suggestion is unclear, ask the user before drafting. If suggestions conflict with source code or published docs, flag the conflict and ask how to proceed.",{"type":52,"tag":538,"props":1735,"children":1737},{"id":1736},"_0d-parse-open-questions",[1738],{"type":57,"value":1739},"0d. Parse open questions",{"type":52,"tag":53,"props":1741,"children":1742},{},[1743,1745,1750,1752,1757],{"type":57,"value":1744},"Scan the issue ",{"type":52,"tag":68,"props":1746,"children":1748},{"className":1747},[],[1749],{"type":57,"value":1219},{"type":57,"value":1751}," and ",{"type":52,"tag":68,"props":1753,"children":1755},{"className":1754},[],[1756],{"type":57,"value":1200},{"type":57,"value":1758}," for unresolved items. Common locations and formats:",{"type":52,"tag":116,"props":1760,"children":1761},{},[1762,1801,1812,1851],{"type":52,"tag":120,"props":1763,"children":1764},{},[1765,1767,1773,1774,1780,1781,1787,1788,1794,1795],{"type":57,"value":1766},"Headings: ",{"type":52,"tag":68,"props":1768,"children":1770},{"className":1769},[],[1771],{"type":57,"value":1772},"## Open items to confirm before publishing",{"type":57,"value":693},{"type":52,"tag":68,"props":1775,"children":1777},{"className":1776},[],[1778],{"type":57,"value":1779},"## Open questions",{"type":57,"value":693},{"type":52,"tag":68,"props":1782,"children":1784},{"className":1783},[],[1785],{"type":57,"value":1786},"## Questions",{"type":57,"value":693},{"type":52,"tag":68,"props":1789,"children":1791},{"className":1790},[],[1792],{"type":57,"value":1793},"## Unknowns",{"type":57,"value":693},{"type":52,"tag":68,"props":1796,"children":1798},{"className":1797},[],[1799],{"type":57,"value":1800},"## Decisions needed",{"type":52,"tag":120,"props":1802,"children":1803},{},[1804,1806],{"type":57,"value":1805},"Checklist items still open: ",{"type":52,"tag":68,"props":1807,"children":1809},{"className":1808},[],[1810],{"type":57,"value":1811},"- [ ] ...",{"type":52,"tag":120,"props":1813,"children":1814},{},[1815,1817,1823,1824,1830,1831,1837,1838,1844,1845],{"type":57,"value":1816},"Explicit markers: ",{"type":52,"tag":68,"props":1818,"children":1820},{"className":1819},[],[1821],{"type":57,"value":1822},"TBD",{"type":57,"value":693},{"type":52,"tag":68,"props":1825,"children":1827},{"className":1826},[],[1828],{"type":57,"value":1829},"TODO",{"type":57,"value":693},{"type":52,"tag":68,"props":1832,"children":1834},{"className":1833},[],[1835],{"type":57,"value":1836},"?",{"type":57,"value":693},{"type":52,"tag":68,"props":1839,"children":1841},{"className":1840},[],[1842],{"type":57,"value":1843},"Need input from",{"type":57,"value":693},{"type":52,"tag":68,"props":1846,"children":1848},{"className":1847},[],[1849],{"type":57,"value":1850},"Blocked on",{"type":52,"tag":120,"props":1852,"children":1853},{},[1854,1856],{"type":57,"value":1855},"Numbered or bulleted questions ending with ",{"type":52,"tag":68,"props":1857,"children":1859},{"className":1858},[],[1860],{"type":57,"value":1836},{"type":52,"tag":53,"props":1862,"children":1863},{},[1864],{"type":57,"value":1865},"For each question, classify as:",{"type":52,"tag":116,"props":1867,"children":1868},{},[1869,1879,1889],{"type":52,"tag":120,"props":1870,"children":1871},{},[1872,1877],{"type":52,"tag":60,"props":1873,"children":1874},{},[1875],{"type":57,"value":1876},"Resolved",{"type":57,"value":1878}," — answered in the issue body, a comment, or a linked PR\u002Fdescription",{"type":52,"tag":120,"props":1880,"children":1881},{},[1882,1887],{"type":52,"tag":60,"props":1883,"children":1884},{},[1885],{"type":57,"value":1886},"Unresolved",{"type":57,"value":1888}," — still open or contradictory across comments",{"type":52,"tag":120,"props":1890,"children":1891},{},[1892,1897],{"type":52,"tag":60,"props":1893,"children":1894},{},[1895],{"type":57,"value":1896},"Researchable",{"type":57,"value":1898}," — answerable from Kibana source or published docs without asking the user (handle in Step 2; do not ask the user)",{"type":52,"tag":53,"props":1900,"children":1901},{},[1902],{"type":57,"value":1903},"Present the parsed list to the user before drafting:",{"type":52,"tag":819,"props":1905,"children":1907},{"className":1536,"code":1906,"language":1538,"meta":824,"style":824},"## Intake summary\n- **Issue**: elastic\u002Fdocs-content-internal#456 — \u003Ctitle>\n- **Scope**: ...\n- **Page type**: ...\n- **Target path**: ...\n\n## Suggested documentation work\n| # | Suggestion (from issue) | Status |\n|---|-------------------------|--------|\n| 1 | ... | Addressed \u002F Deferred \u002F Blocked |\n\n## Open questions\n| # | Question | Status |\n|---|----------|--------|\n| 1 | ... | Resolved — see comment by @user |\n| 2 | ... | Unresolved |\n| 3 | ... | Researchable — will verify in Kibana source |\n",[1908],{"type":52,"tag":68,"props":1909,"children":1910},{"__ignoreMap":824},[1911,1923,1953,1977,2000,2023,2031,2043,2075,2082,2116,2124,2137,2170,2179,2212,2245],{"type":52,"tag":830,"props":1912,"children":1913},{"class":832,"line":833},[1914,1918],{"type":52,"tag":830,"props":1915,"children":1916},{"style":854},[1917],{"type":57,"value":1550},{"type":52,"tag":830,"props":1919,"children":1920},{"style":837},[1921],{"type":57,"value":1922},"Intake summary\n",{"type":52,"tag":830,"props":1924,"children":1925},{"class":832,"line":896},[1926,1931,1937,1943,1948],{"type":52,"tag":830,"props":1927,"children":1928},{"style":854},[1929],{"type":57,"value":1930},"-",{"type":52,"tag":830,"props":1932,"children":1934},{"style":1933},"--shiki-light:#39ADB5;--shiki-light-font-weight:bold;--shiki-default:#89DDFF;--shiki-default-font-weight:bold;--shiki-dark:#89DDFF;--shiki-dark-font-weight:bold",[1935],{"type":57,"value":1936}," **",{"type":52,"tag":830,"props":1938,"children":1940},{"style":1939},"--shiki-light:#E53935;--shiki-light-font-weight:bold;--shiki-default:#F07178;--shiki-default-font-weight:bold;--shiki-dark:#F07178;--shiki-dark-font-weight:bold",[1941],{"type":57,"value":1942},"Issue",{"type":52,"tag":830,"props":1944,"children":1945},{"style":1933},[1946],{"type":57,"value":1947},"**",{"type":52,"tag":830,"props":1949,"children":1950},{"style":865},[1951],{"type":57,"value":1952},": elastic\u002Fdocs-content-internal#456 — \u003Ctitle>\n",{"type":52,"tag":830,"props":1954,"children":1955},{"class":832,"line":906},[1956,1960,1964,1968,1972],{"type":52,"tag":830,"props":1957,"children":1958},{"style":854},[1959],{"type":57,"value":1930},{"type":52,"tag":830,"props":1961,"children":1962},{"style":1933},[1963],{"type":57,"value":1936},{"type":52,"tag":830,"props":1965,"children":1966},{"style":1939},[1967],{"type":57,"value":1008},{"type":52,"tag":830,"props":1969,"children":1970},{"style":1933},[1971],{"type":57,"value":1947},{"type":52,"tag":830,"props":1973,"children":1974},{"style":865},[1975],{"type":57,"value":1976},": ...\n",{"type":52,"tag":830,"props":1978,"children":1979},{"class":832,"line":1602},[1980,1984,1988,1992,1996],{"type":52,"tag":830,"props":1981,"children":1982},{"style":854},[1983],{"type":57,"value":1930},{"type":52,"tag":830,"props":1985,"children":1986},{"style":1933},[1987],{"type":57,"value":1936},{"type":52,"tag":830,"props":1989,"children":1990},{"style":1939},[1991],{"type":57,"value":1024},{"type":52,"tag":830,"props":1993,"children":1994},{"style":1933},[1995],{"type":57,"value":1947},{"type":52,"tag":830,"props":1997,"children":1998},{"style":865},[1999],{"type":57,"value":1976},{"type":52,"tag":830,"props":2001,"children":2002},{"class":832,"line":1656},[2003,2007,2011,2015,2019],{"type":52,"tag":830,"props":2004,"children":2005},{"style":854},[2006],{"type":57,"value":1930},{"type":52,"tag":830,"props":2008,"children":2009},{"style":1933},[2010],{"type":57,"value":1936},{"type":52,"tag":830,"props":2012,"children":2013},{"style":1939},[2014],{"type":57,"value":1037},{"type":52,"tag":830,"props":2016,"children":2017},{"style":1933},[2018],{"type":57,"value":1947},{"type":52,"tag":830,"props":2020,"children":2021},{"style":865},[2022],{"type":57,"value":1976},{"type":52,"tag":830,"props":2024,"children":2025},{"class":832,"line":1691},[2026],{"type":52,"tag":830,"props":2027,"children":2028},{"emptyLinePlaceholder":36},[2029],{"type":57,"value":2030},"\n",{"type":52,"tag":830,"props":2032,"children":2034},{"class":832,"line":2033},7,[2035,2039],{"type":52,"tag":830,"props":2036,"children":2037},{"style":854},[2038],{"type":57,"value":1550},{"type":52,"tag":830,"props":2040,"children":2041},{"style":837},[2042],{"type":57,"value":1555},{"type":52,"tag":830,"props":2044,"children":2046},{"class":832,"line":2045},8,[2047,2051,2055,2059,2063,2067,2071],{"type":52,"tag":830,"props":2048,"children":2049},{"style":854},[2050],{"type":57,"value":1563},{"type":52,"tag":830,"props":2052,"children":2053},{"style":865},[2054],{"type":57,"value":1568},{"type":52,"tag":830,"props":2056,"children":2057},{"style":854},[2058],{"type":57,"value":1563},{"type":52,"tag":830,"props":2060,"children":2061},{"style":865},[2062],{"type":57,"value":1577},{"type":52,"tag":830,"props":2064,"children":2065},{"style":854},[2066],{"type":57,"value":1563},{"type":52,"tag":830,"props":2068,"children":2069},{"style":865},[2070],{"type":57,"value":1586},{"type":52,"tag":830,"props":2072,"children":2073},{"style":854},[2074],{"type":57,"value":1591},{"type":52,"tag":830,"props":2076,"children":2077},{"class":832,"line":23},[2078],{"type":52,"tag":830,"props":2079,"children":2080},{"style":854},[2081],{"type":57,"value":1599},{"type":52,"tag":830,"props":2083,"children":2085},{"class":832,"line":2084},10,[2086,2090,2094,2098,2103,2107,2112],{"type":52,"tag":830,"props":2087,"children":2088},{"style":854},[2089],{"type":57,"value":1563},{"type":52,"tag":830,"props":2091,"children":2092},{"style":865},[2093],{"type":57,"value":1612},{"type":52,"tag":830,"props":2095,"children":2096},{"style":854},[2097],{"type":57,"value":1563},{"type":52,"tag":830,"props":2099,"children":2100},{"style":865},[2101],{"type":57,"value":2102}," ... ",{"type":52,"tag":830,"props":2104,"children":2105},{"style":854},[2106],{"type":57,"value":1563},{"type":52,"tag":830,"props":2108,"children":2109},{"style":865},[2110],{"type":57,"value":2111}," Addressed \u002F Deferred \u002F Blocked ",{"type":52,"tag":830,"props":2113,"children":2114},{"style":854},[2115],{"type":57,"value":1591},{"type":52,"tag":830,"props":2117,"children":2119},{"class":832,"line":2118},11,[2120],{"type":52,"tag":830,"props":2121,"children":2122},{"emptyLinePlaceholder":36},[2123],{"type":57,"value":2030},{"type":52,"tag":830,"props":2125,"children":2127},{"class":832,"line":2126},12,[2128,2132],{"type":52,"tag":830,"props":2129,"children":2130},{"style":854},[2131],{"type":57,"value":1550},{"type":52,"tag":830,"props":2133,"children":2134},{"style":837},[2135],{"type":57,"value":2136},"Open questions\n",{"type":52,"tag":830,"props":2138,"children":2140},{"class":832,"line":2139},13,[2141,2145,2149,2153,2158,2162,2166],{"type":52,"tag":830,"props":2142,"children":2143},{"style":854},[2144],{"type":57,"value":1563},{"type":52,"tag":830,"props":2146,"children":2147},{"style":865},[2148],{"type":57,"value":1568},{"type":52,"tag":830,"props":2150,"children":2151},{"style":854},[2152],{"type":57,"value":1563},{"type":52,"tag":830,"props":2154,"children":2155},{"style":865},[2156],{"type":57,"value":2157}," Question ",{"type":52,"tag":830,"props":2159,"children":2160},{"style":854},[2161],{"type":57,"value":1563},{"type":52,"tag":830,"props":2163,"children":2164},{"style":865},[2165],{"type":57,"value":1586},{"type":52,"tag":830,"props":2167,"children":2168},{"style":854},[2169],{"type":57,"value":1591},{"type":52,"tag":830,"props":2171,"children":2173},{"class":832,"line":2172},14,[2174],{"type":52,"tag":830,"props":2175,"children":2176},{"style":854},[2177],{"type":57,"value":2178},"|---|----------|--------|\n",{"type":52,"tag":830,"props":2180,"children":2182},{"class":832,"line":2181},15,[2183,2187,2191,2195,2199,2203,2208],{"type":52,"tag":830,"props":2184,"children":2185},{"style":854},[2186],{"type":57,"value":1563},{"type":52,"tag":830,"props":2188,"children":2189},{"style":865},[2190],{"type":57,"value":1612},{"type":52,"tag":830,"props":2192,"children":2193},{"style":854},[2194],{"type":57,"value":1563},{"type":52,"tag":830,"props":2196,"children":2197},{"style":865},[2198],{"type":57,"value":2102},{"type":52,"tag":830,"props":2200,"children":2201},{"style":854},[2202],{"type":57,"value":1563},{"type":52,"tag":830,"props":2204,"children":2205},{"style":865},[2206],{"type":57,"value":2207}," Resolved — see comment by @user ",{"type":52,"tag":830,"props":2209,"children":2210},{"style":854},[2211],{"type":57,"value":1591},{"type":52,"tag":830,"props":2213,"children":2215},{"class":832,"line":2214},16,[2216,2220,2224,2228,2232,2236,2241],{"type":52,"tag":830,"props":2217,"children":2218},{"style":854},[2219],{"type":57,"value":1563},{"type":52,"tag":830,"props":2221,"children":2222},{"style":865},[2223],{"type":57,"value":1666},{"type":52,"tag":830,"props":2225,"children":2226},{"style":854},[2227],{"type":57,"value":1563},{"type":52,"tag":830,"props":2229,"children":2230},{"style":865},[2231],{"type":57,"value":2102},{"type":52,"tag":830,"props":2233,"children":2234},{"style":854},[2235],{"type":57,"value":1563},{"type":52,"tag":830,"props":2237,"children":2238},{"style":865},[2239],{"type":57,"value":2240}," Unresolved ",{"type":52,"tag":830,"props":2242,"children":2243},{"style":854},[2244],{"type":57,"value":1591},{"type":52,"tag":830,"props":2246,"children":2248},{"class":832,"line":2247},17,[2249,2253,2257,2261,2265,2269,2274],{"type":52,"tag":830,"props":2250,"children":2251},{"style":854},[2252],{"type":57,"value":1563},{"type":52,"tag":830,"props":2254,"children":2255},{"style":865},[2256],{"type":57,"value":1701},{"type":52,"tag":830,"props":2258,"children":2259},{"style":854},[2260],{"type":57,"value":1563},{"type":52,"tag":830,"props":2262,"children":2263},{"style":865},[2264],{"type":57,"value":2102},{"type":52,"tag":830,"props":2266,"children":2267},{"style":854},[2268],{"type":57,"value":1563},{"type":52,"tag":830,"props":2270,"children":2271},{"style":865},[2272],{"type":57,"value":2273}," Researchable — will verify in Kibana source ",{"type":52,"tag":830,"props":2275,"children":2276},{"style":854},[2277],{"type":57,"value":1591},{"type":52,"tag":538,"props":2279,"children":2281},{"id":2280},"_0e-ask-the-user-to-answer-unresolved-questions",[2282],{"type":57,"value":2283},"0e. Ask the user to answer unresolved questions",{"type":52,"tag":53,"props":2285,"children":2286},{},[2287,2289,2293,2295,2300],{"type":57,"value":2288},"If any questions are ",{"type":52,"tag":60,"props":2290,"children":2291},{},[2292],{"type":57,"value":1886},{"type":57,"value":2294},", use ",{"type":52,"tag":68,"props":2296,"children":2298},{"className":2297},[],[2299],{"type":57,"value":561},{"type":57,"value":2301}," to collect answers. Rules:",{"type":52,"tag":116,"props":2303,"children":2304},{},[2305,2317,2322,2327],{"type":52,"tag":120,"props":2306,"children":2307},{},[2308,2310,2315],{"type":57,"value":2309},"Ask only ",{"type":52,"tag":60,"props":2311,"children":2312},{},[2313],{"type":57,"value":2314},"unresolved",{"type":57,"value":2316}," questions — skip resolved and researchable items",{"type":52,"tag":120,"props":2318,"children":2319},{},[2320],{"type":57,"value":2321},"Batch related questions in one form when possible (max ~5 per round)",{"type":52,"tag":120,"props":2323,"children":2324},{},[2325],{"type":57,"value":2326},"Quote the original question text from the issue so the user recognizes it",{"type":52,"tag":120,"props":2328,"children":2329},{},[2330,2332],{"type":57,"value":2331},"If a question has multiple-choice options implied by the issue, offer those as choices plus ",{"type":52,"tag":60,"props":2333,"children":2334},{},[2335],{"type":57,"value":2336},"Other",{"type":52,"tag":53,"props":2338,"children":2339},{},[2340],{"type":57,"value":2341},"Example prompt:",{"type":52,"tag":565,"props":2343,"children":2344},{},[2345,2350],{"type":52,"tag":53,"props":2346,"children":2347},{},[2348],{"type":57,"value":2349},"The doc issue lists these open questions. Please answer before I draft:",{"type":52,"tag":204,"props":2351,"children":2352},{},[2353,2358],{"type":52,"tag":120,"props":2354,"children":2355},{},[2356],{"type":57,"value":2357},"Should this page cover stack 9.4 only or include 9.5+ inputs placement?",{"type":52,"tag":120,"props":2359,"children":2360},{},[2361,2363,2369],{"type":57,"value":2362},"Is ",{"type":52,"tag":68,"props":2364,"children":2366},{"className":2365},[],[2367],{"type":57,"value":2368},"workflow.executeAsync",{"type":57,"value":2370}," in scope or out of scope for this use case page?",{"type":52,"tag":53,"props":2372,"children":2373},{},[2374,2379],{"type":52,"tag":60,"props":2375,"children":2376},{},[2377],{"type":57,"value":2378},"Do not proceed to Step 2 (research) or Step 4 (draft)",{"type":57,"value":2380}," until:",{"type":52,"tag":116,"props":2382,"children":2383},{},[2384,2394],{"type":52,"tag":120,"props":2385,"children":2386},{},[2387,2389],{"type":57,"value":2388},"All unresolved questions have answers, ",{"type":52,"tag":60,"props":2390,"children":2391},{},[2392],{"type":57,"value":2393},"or",{"type":52,"tag":120,"props":2395,"children":2396},{},[2397],{"type":57,"value":2398},"The user explicitly says to proceed with stated assumptions (record those assumptions in the output)",{"type":52,"tag":53,"props":2400,"children":2401},{},[2402],{"type":57,"value":2403},"After answers are collected, update the intake summary and suggested-work status table. If an answer changes page type, target path, or scope of suggested work, re-check classification in Step 1.",{"type":52,"tag":77,"props":2405,"children":2407},{"id":2406},"step-1-classify-the-page",[2408],{"type":57,"value":2409},"Step 1: Classify the page",{"type":52,"tag":53,"props":2411,"children":2412},{},[2413,2415,2419,2420,2425],{"type":57,"value":2414},"Determine which page type to draft. Use the ",{"type":52,"tag":60,"props":2416,"children":2417},{},[2418],{"type":57,"value":967},{"type":57,"value":1751},{"type":52,"tag":60,"props":2421,"children":2422},{},[2423],{"type":57,"value":2424},"suggested documentation work",{"type":57,"value":2426}," from Step 0 when available. Ask one focused question if still unclear.",{"type":52,"tag":361,"props":2428,"children":2429},{},[2430,2455],{"type":52,"tag":365,"props":2431,"children":2432},{},[2433],{"type":52,"tag":369,"props":2434,"children":2435},{},[2436,2440,2445,2450],{"type":52,"tag":373,"props":2437,"children":2438},{},[2439],{"type":57,"value":1024},{"type":52,"tag":373,"props":2441,"children":2442},{},[2443],{"type":57,"value":2444},"Typical location",{"type":52,"tag":373,"props":2446,"children":2447},{},[2448],{"type":57,"value":2449},"Content type",{"type":52,"tag":373,"props":2451,"children":2452},{},[2453],{"type":57,"value":2454},"Example",{"type":52,"tag":389,"props":2456,"children":2457},{},[2458,2488,2518,2548,2578,2606,2635],{"type":52,"tag":369,"props":2459,"children":2460},{},[2461,2469,2478,2483],{"type":52,"tag":396,"props":2462,"children":2463},{},[2464],{"type":52,"tag":60,"props":2465,"children":2466},{},[2467],{"type":57,"value":2468},"Step reference",{"type":52,"tag":396,"props":2470,"children":2471},{},[2472],{"type":52,"tag":68,"props":2473,"children":2475},{"className":2474},[],[2476],{"type":57,"value":2477},"explore-analyze\u002Fworkflows\u002Fsteps\u002F",{"type":52,"tag":396,"props":2479,"children":2480},{},[2481],{"type":57,"value":2482},"Reference",{"type":52,"tag":396,"props":2484,"children":2485},{},[2486],{"type":57,"value":2487},"Elasticsearch action steps",{"type":52,"tag":369,"props":2489,"children":2490},{},[2491,2499,2508,2513],{"type":52,"tag":396,"props":2492,"children":2493},{},[2494],{"type":52,"tag":60,"props":2495,"children":2496},{},[2497],{"type":57,"value":2498},"Use case",{"type":52,"tag":396,"props":2500,"children":2501},{},[2502],{"type":52,"tag":68,"props":2503,"children":2505},{"className":2504},[],[2506],{"type":57,"value":2507},"explore-analyze\u002Fworkflows\u002Fuse-cases\u002F",{"type":52,"tag":396,"props":2509,"children":2510},{},[2511],{"type":57,"value":2512},"Overview \u002F explanation",{"type":52,"tag":396,"props":2514,"children":2515},{},[2516],{"type":57,"value":2517},"Security workflows",{"type":52,"tag":369,"props":2519,"children":2520},{},[2521,2529,2538,2543],{"type":52,"tag":396,"props":2522,"children":2523},{},[2524],{"type":52,"tag":60,"props":2525,"children":2526},{},[2527],{"type":57,"value":2528},"Authoring technique",{"type":52,"tag":396,"props":2530,"children":2531},{},[2532],{"type":52,"tag":68,"props":2533,"children":2535},{"className":2534},[],[2536],{"type":57,"value":2537},"explore-analyze\u002Fworkflows\u002Fauthoring-techniques\u002F",{"type":52,"tag":396,"props":2539,"children":2540},{},[2541],{"type":57,"value":2542},"How-to",{"type":52,"tag":396,"props":2544,"children":2545},{},[2546],{"type":57,"value":2547},"Manage and organize workflows",{"type":52,"tag":369,"props":2549,"children":2550},{},[2551,2559,2568,2573],{"type":52,"tag":396,"props":2552,"children":2553},{},[2554],{"type":52,"tag":60,"props":2555,"children":2556},{},[2557],{"type":57,"value":2558},"Concept",{"type":52,"tag":396,"props":2560,"children":2561},{},[2562],{"type":52,"tag":68,"props":2563,"children":2565},{"className":2564},[],[2566],{"type":57,"value":2567},"explore-analyze\u002Fworkflows\u002Fconcepts\u002F",{"type":52,"tag":396,"props":2569,"children":2570},{},[2571],{"type":57,"value":2572},"Explanation",{"type":52,"tag":396,"props":2574,"children":2575},{},[2576],{"type":57,"value":2577},"Triggers, Steps, Liquid",{"type":52,"tag":369,"props":2579,"children":2580},{},[2581,2588,2597,2601],{"type":52,"tag":396,"props":2582,"children":2583},{},[2584],{"type":52,"tag":60,"props":2585,"children":2586},{},[2587],{"type":57,"value":2482},{"type":52,"tag":396,"props":2589,"children":2590},{},[2591],{"type":52,"tag":68,"props":2592,"children":2594},{"className":2593},[],[2595],{"type":57,"value":2596},"explore-analyze\u002Fworkflows\u002Freference\u002F",{"type":52,"tag":396,"props":2598,"children":2599},{},[2600],{"type":57,"value":2482},{"type":52,"tag":396,"props":2602,"children":2603},{},[2604],{"type":57,"value":2605},"Cheat sheet, step type index",{"type":52,"tag":369,"props":2607,"children":2608},{},[2609,2617,2626,2630],{"type":52,"tag":396,"props":2610,"children":2611},{},[2612],{"type":52,"tag":60,"props":2613,"children":2614},{},[2615],{"type":57,"value":2616},"Tutorial",{"type":52,"tag":396,"props":2618,"children":2619},{},[2620],{"type":52,"tag":68,"props":2621,"children":2623},{"className":2622},[],[2624],{"type":57,"value":2625},"explore-analyze\u002Fworkflows\u002Fget-started\u002F",{"type":52,"tag":396,"props":2627,"children":2628},{},[2629],{"type":57,"value":2616},{"type":52,"tag":396,"props":2631,"children":2632},{},[2633],{"type":57,"value":2634},"Build your first workflow",{"type":52,"tag":369,"props":2636,"children":2637},{},[2638,2646,2656,2661],{"type":52,"tag":396,"props":2639,"children":2640},{},[2641],{"type":52,"tag":60,"props":2642,"children":2643},{},[2644],{"type":57,"value":2645},"Hub \u002F overview",{"type":52,"tag":396,"props":2647,"children":2648},{},[2649,2654],{"type":52,"tag":68,"props":2650,"children":2652},{"className":2651},[],[2653],{"type":57,"value":73},{"type":57,"value":2655}," or a section index",{"type":52,"tag":396,"props":2657,"children":2658},{},[2659],{"type":57,"value":2660},"Overview",{"type":52,"tag":396,"props":2662,"children":2663},{},[2664],{"type":57,"value":2665},"Workflows, Use cases",{"type":52,"tag":53,"props":2667,"children":2668},{},[2669,2671,2680],{"type":57,"value":2670},"Run ",{"type":52,"tag":344,"props":2672,"children":2674},{"href":452,"rel":2673},[347],[2675],{"type":52,"tag":68,"props":2676,"children":2678},{"className":2677},[],[2679],{"type":57,"value":447},{"type":57,"value":2681}," in classify mode when the page type is ambiguous — skip if not installed.",{"type":52,"tag":77,"props":2683,"children":2685},{"id":2684},"step-2-research-before-writing",[2686],{"type":57,"value":2687},"Step 2: Research before writing",{"type":52,"tag":53,"props":2689,"children":2690},{},[2691],{"type":57,"value":2692},"Never guess step types, parameter names, or UI labels. Gather facts first.",{"type":52,"tag":538,"props":2694,"children":2696},{"id":2695},"published-docs-preferred",[2697],{"type":57,"value":2698},"Published docs (preferred)",{"type":52,"tag":53,"props":2700,"children":2701},{},[2702,2704,2709,2711,2716,2718,2722,2724,2729],{"type":57,"value":2703},"Use the ",{"type":52,"tag":60,"props":2705,"children":2706},{},[2707],{"type":57,"value":2708},"elastic-docs",{"type":57,"value":2710}," MCP server at ",{"type":52,"tag":68,"props":2712,"children":2714},{"className":2713},[],[2715],{"type":57,"value":414},{"type":57,"value":2717}," (see ",{"type":52,"tag":60,"props":2719,"children":2720},{},[2721],{"type":57,"value":337},{"type":57,"value":2723}," for setup). If MCP is unavailable, use WebFetch on the same ",{"type":52,"tag":68,"props":2725,"children":2727},{"className":2726},[],[2728],{"type":57,"value":523},{"type":57,"value":2730}," URLs.",{"type":52,"tag":204,"props":2732,"children":2733},{},[2734,2745,2762],{"type":52,"tag":120,"props":2735,"children":2736},{},[2737,2743],{"type":52,"tag":68,"props":2738,"children":2740},{"className":2739},[],[2741],{"type":57,"value":2742},"search_docs",{"type":57,"value":2744}," — find existing pages on the topic and related building blocks",{"type":52,"tag":120,"props":2746,"children":2747},{},[2748,2754,2756],{"type":52,"tag":68,"props":2749,"children":2751},{"className":2750},[],[2752],{"type":57,"value":2753},"get_document_by_url",{"type":57,"value":2755}," — fetch sibling pages, templates, and guidelines with ",{"type":52,"tag":68,"props":2757,"children":2759},{"className":2758},[],[2760],{"type":57,"value":2761},"includeBody: true",{"type":52,"tag":120,"props":2763,"children":2764},{},[2765,2771],{"type":52,"tag":68,"props":2766,"children":2768},{"className":2767},[],[2769],{"type":57,"value":2770},"find_related_docs",{"type":57,"value":2772}," — discover cross-link targets",{"type":52,"tag":53,"props":2774,"children":2775},{},[2776],{"type":57,"value":2777},"Always read these anchors before drafting:",{"type":52,"tag":361,"props":2779,"children":2780},{},[2781,2796],{"type":52,"tag":365,"props":2782,"children":2783},{},[2784],{"type":52,"tag":369,"props":2785,"children":2786},{},[2787,2791],{"type":52,"tag":373,"props":2788,"children":2789},{},[2790],{"type":57,"value":377},{"type":52,"tag":373,"props":2792,"children":2793},{},[2794],{"type":57,"value":2795},"URL path",{"type":52,"tag":389,"props":2797,"children":2798},{},[2799,2816,2833,2850,2867],{"type":52,"tag":369,"props":2800,"children":2801},{},[2802,2807],{"type":52,"tag":396,"props":2803,"children":2804},{},[2805],{"type":57,"value":2806},"Workflows hub",{"type":52,"tag":396,"props":2808,"children":2809},{},[2810],{"type":52,"tag":68,"props":2811,"children":2813},{"className":2812},[],[2814],{"type":57,"value":2815},"\u002Fdocs\u002Fexplore-analyze\u002Fworkflows",{"type":52,"tag":369,"props":2817,"children":2818},{},[2819,2824],{"type":52,"tag":396,"props":2820,"children":2821},{},[2822],{"type":57,"value":2823},"Cheat sheet (gotchas)",{"type":52,"tag":396,"props":2825,"children":2826},{},[2827],{"type":52,"tag":68,"props":2828,"children":2830},{"className":2829},[],[2831],{"type":57,"value":2832},"\u002Fdocs\u002Fexplore-analyze\u002Fworkflows\u002Freference\u002Fcheat-sheet",{"type":52,"tag":369,"props":2834,"children":2835},{},[2836,2841],{"type":52,"tag":396,"props":2837,"children":2838},{},[2839],{"type":57,"value":2840},"Step type index",{"type":52,"tag":396,"props":2842,"children":2843},{},[2844],{"type":52,"tag":68,"props":2845,"children":2847},{"className":2846},[],[2848],{"type":57,"value":2849},"\u002Fdocs\u002Fexplore-analyze\u002Fworkflows\u002Freference\u002Fstep-types",{"type":52,"tag":369,"props":2851,"children":2852},{},[2853,2858],{"type":52,"tag":396,"props":2854,"children":2855},{},[2856],{"type":57,"value":2857},"Anatomy reference",{"type":52,"tag":396,"props":2859,"children":2860},{},[2861],{"type":52,"tag":68,"props":2862,"children":2864},{"className":2863},[],[2865],{"type":57,"value":2866},"\u002Fdocs\u002Fexplore-analyze\u002Fworkflows\u002Fauthoring-techniques\u002Fanatomy",{"type":52,"tag":369,"props":2868,"children":2869},{},[2870,2875],{"type":52,"tag":396,"props":2871,"children":2872},{},[2873],{"type":57,"value":2874},"Choose the right step",{"type":52,"tag":396,"props":2876,"children":2877},{},[2878],{"type":52,"tag":68,"props":2879,"children":2881},{"className":2880},[],[2882],{"type":57,"value":2883},"\u002Fdocs\u002Fexplore-analyze\u002Fworkflows\u002Fauthoring-techniques\u002Fchoose-the-right-step",{"type":52,"tag":538,"props":2885,"children":2887},{"id":2886},"kibana-source-code",[2888],{"type":57,"value":2889},"Kibana source code",{"type":52,"tag":53,"props":2891,"children":2892},{},[2893],{"type":57,"value":2894},"When documenting a step type, trigger, or UI workflow:",{"type":52,"tag":204,"props":2896,"children":2897},{},[2898,2938,2943],{"type":52,"tag":120,"props":2899,"children":2900},{},[2901,2903,2909,2910,2916,2917,2922,2923,2929,2930,2936],{"type":57,"value":2902},"Search the Kibana repo for the step type identifier (e.g., ",{"type":52,"tag":68,"props":2904,"children":2906},{"className":2905},[],[2907],{"type":57,"value":2908},"elasticsearch.search",{"type":57,"value":693},{"type":52,"tag":68,"props":2911,"children":2913},{"className":2912},[],[2914],{"type":57,"value":2915},"cases.addComment",{"type":57,"value":693},{"type":52,"tag":68,"props":2918,"children":2920},{"className":2919},[],[2921],{"type":57,"value":290},{"type":57,"value":693},{"type":52,"tag":68,"props":2924,"children":2926},{"className":2925},[],[2927],{"type":57,"value":2928},"slack.postMessage",{"type":57,"value":693},{"type":52,"tag":68,"props":2931,"children":2933},{"className":2932},[],[2934],{"type":57,"value":2935},"foreach",{"type":57,"value":2937},")",{"type":52,"tag":120,"props":2939,"children":2940},{},[2941],{"type":57,"value":2942},"Read the step definition, schema, or connector action registration — not just examples",{"type":52,"tag":120,"props":2944,"children":2945},{},[2946],{"type":57,"value":2947},"Confirm parameter names, required fields, and output shape",{"type":52,"tag":53,"props":2949,"children":2950},{},[2951],{"type":57,"value":2952},"Likely starting points in Kibana — search by step type ID first, then use the path that matches what you are documenting:",{"type":52,"tag":361,"props":2954,"children":2955},{},[2956,2971],{"type":52,"tag":365,"props":2957,"children":2958},{},[2959],{"type":52,"tag":369,"props":2960,"children":2961},{},[2962,2967],{"type":52,"tag":373,"props":2963,"children":2964},{},[2965],{"type":57,"value":2966},"What you need",{"type":52,"tag":373,"props":2968,"children":2969},{},[2970],{"type":57,"value":987},{"type":52,"tag":389,"props":2972,"children":2973},{},[2974,3031,3107,3137,3165,3185,3213],{"type":52,"tag":369,"props":2975,"children":2976},{},[2977,2985],{"type":52,"tag":396,"props":2978,"children":2979},{},[2980],{"type":52,"tag":60,"props":2981,"children":2982},{},[2983],{"type":57,"value":2984},"Step parameters, workflow YAML schema, deprecations",{"type":52,"tag":396,"props":2986,"children":2987},{},[2988,2994,2996,3002,3003,3009,3010,3016,3018,3024,3025],{"type":52,"tag":68,"props":2989,"children":2991},{"className":2990},[],[2992],{"type":57,"value":2993},"src\u002Fplatform\u002Fpackages\u002Fshared\u002Fkbn-workflows\u002Fspec\u002F",{"type":57,"value":2995}," — start with ",{"type":52,"tag":68,"props":2997,"children":2999},{"className":2998},[],[3000],{"type":57,"value":3001},"schema.ts",{"type":57,"value":693},{"type":52,"tag":68,"props":3004,"children":3006},{"className":3005},[],[3007],{"type":57,"value":3008},"builtin_step_definitions.ts",{"type":57,"value":693},{"type":52,"tag":68,"props":3011,"children":3013},{"className":3012},[],[3014],{"type":57,"value":3015},"builtin_trigger_definitions.ts",{"type":57,"value":3017},", and namespace dirs ",{"type":52,"tag":68,"props":3019,"children":3021},{"className":3020},[],[3022],{"type":57,"value":3023},"spec\u002Felasticsearch\u002F",{"type":57,"value":693},{"type":52,"tag":68,"props":3026,"children":3028},{"className":3027},[],[3029],{"type":57,"value":3030},"spec\u002Fkibana\u002F",{"type":52,"tag":369,"props":3032,"children":3033},{},[3034,3082],{"type":52,"tag":396,"props":3035,"children":3036},{},[3037,3042,3044,3049,3050,3055,3056,3062,3063,3068,3069,3074,3075,3080],{"type":52,"tag":60,"props":3038,"children":3039},{},[3040],{"type":57,"value":3041},"A specific step type",{"type":57,"value":3043}," (",{"type":52,"tag":68,"props":3045,"children":3047},{"className":3046},[],[3048],{"type":57,"value":2908},{"type":57,"value":693},{"type":52,"tag":68,"props":3051,"children":3053},{"className":3052},[],[3054],{"type":57,"value":2915},{"type":57,"value":693},{"type":52,"tag":68,"props":3057,"children":3059},{"className":3058},[],[3060],{"type":57,"value":3061},"security.setAlertStatus",{"type":57,"value":693},{"type":52,"tag":68,"props":3064,"children":3066},{"className":3065},[],[3067],{"type":57,"value":290},{"type":57,"value":693},{"type":52,"tag":68,"props":3070,"children":3072},{"className":3071},[],[3073],{"type":57,"value":2928},{"type":57,"value":693},{"type":52,"tag":68,"props":3076,"children":3078},{"className":3077},[],[3079],{"type":57,"value":2935},{"type":57,"value":3081},", etc.)",{"type":52,"tag":396,"props":3083,"children":3084},{},[3085,3091,3093,3098,3100,3105],{"type":52,"tag":68,"props":3086,"children":3088},{"className":3087},[],[3089],{"type":57,"value":3090},"kbn-workflows\u002Fspec\u002F\u003Cnamespace>\u002F",{"type":57,"value":3092}," for namespaced steps; ",{"type":52,"tag":68,"props":3094,"children":3096},{"className":3095},[],[3097],{"type":57,"value":3008},{"type":57,"value":3099}," for built-ins like ",{"type":52,"tag":68,"props":3101,"children":3103},{"className":3102},[],[3104],{"type":57,"value":2935},{"type":57,"value":3106},"; then the registering plugin via repo search",{"type":52,"tag":369,"props":3108,"children":3109},{},[3110,3120],{"type":52,"tag":396,"props":3111,"children":3112},{},[3113,3118],{"type":52,"tag":60,"props":3114,"children":3115},{},[3116],{"type":57,"value":3117},"Triggers",{"type":57,"value":3119}," (manual, scheduled, alert, event-driven)",{"type":52,"tag":396,"props":3121,"children":3122},{},[3123,3129,3131],{"type":52,"tag":68,"props":3124,"children":3126},{"className":3125},[],[3127],{"type":57,"value":3128},"kbn-workflows\u002Fspec\u002Fbuiltin_trigger_definitions.ts",{"type":57,"value":3130},"; product triggers in registering plugins; ",{"type":52,"tag":68,"props":3132,"children":3134},{"className":3133},[],[3135],{"type":57,"value":3136},"workflows_extensions\u002Fdev_docs\u002FTRIGGERS.md",{"type":52,"tag":369,"props":3138,"children":3139},{},[3140,3148],{"type":52,"tag":396,"props":3141,"children":3142},{},[3143],{"type":52,"tag":60,"props":3144,"children":3145},{},[3146],{"type":57,"value":3147},"UI labels, step menu, YAML editor, authoring surfaces",{"type":52,"tag":396,"props":3149,"children":3150},{},[3151,3157,3159],{"type":52,"tag":68,"props":3152,"children":3154},{"className":3153},[],[3155],{"type":57,"value":3156},"src\u002Fplatform\u002Fplugins\u002Fshared\u002Fworkflows_management\u002Fpublic\u002F",{"type":57,"value":3158},"; server-side step discovery in ",{"type":52,"tag":68,"props":3160,"children":3162},{"className":3161},[],[3163],{"type":57,"value":3164},"workflows_management\u002Fserver\u002F",{"type":52,"tag":369,"props":3166,"children":3167},{},[3168,3176],{"type":52,"tag":396,"props":3169,"children":3170},{},[3171],{"type":52,"tag":60,"props":3172,"children":3173},{},[3174],{"type":57,"value":3175},"Execution lifecycle, error handling, step output shape",{"type":52,"tag":396,"props":3177,"children":3178},{},[3179],{"type":52,"tag":68,"props":3180,"children":3182},{"className":3181},[],[3183],{"type":57,"value":3184},"src\u002Fplatform\u002Fplugins\u002Fshared\u002Fworkflows_execution_engine\u002F",{"type":52,"tag":369,"props":3186,"children":3187},{},[3188,3196],{"type":52,"tag":396,"props":3189,"children":3190},{},[3191],{"type":52,"tag":60,"props":3192,"children":3193},{},[3194],{"type":57,"value":3195},"Custom or product-registered steps",{"type":52,"tag":396,"props":3197,"children":3198},{},[3199,3205,3207],{"type":52,"tag":68,"props":3200,"children":3202},{"className":3201},[],[3203],{"type":57,"value":3204},"src\u002Fplatform\u002Fplugins\u002Fshared\u002Fworkflows_extensions\u002F",{"type":57,"value":3206},"; internal guide at ",{"type":52,"tag":68,"props":3208,"children":3210},{"className":3209},[],[3211],{"type":57,"value":3212},"workflows_extensions\u002Fdev_docs\u002FSTEPS.md",{"type":52,"tag":369,"props":3214,"children":3215},{},[3216,3224],{"type":52,"tag":396,"props":3217,"children":3218},{},[3219],{"type":52,"tag":60,"props":3220,"children":3221},{},[3222],{"type":57,"value":3223},"Stack connector actions",{"type":52,"tag":396,"props":3225,"children":3226},{},[3227,3233,3235],{"type":52,"tag":68,"props":3228,"children":3230},{"className":3229},[],[3231],{"type":57,"value":3232},"x-pack\u002Fplatform\u002Fplugins\u002Fshared\u002Fstack_connectors\u002F",{"type":57,"value":3234}," and connector-specific plugins under ",{"type":52,"tag":68,"props":3236,"children":3238},{"className":3237},[],[3239],{"type":57,"value":3240},"x-pack\u002Fplatform\u002Fplugins\u002F",{"type":52,"tag":53,"props":3242,"children":3243},{},[3244,3246,3252,3254,3260],{"type":57,"value":3245},"Official example workflows live in ",{"type":52,"tag":68,"props":3247,"children":3249},{"className":3248},[],[3250],{"type":57,"value":3251},"kbn-workflows\u002Fspec\u002Fexamples\u002F",{"type":57,"value":3253},". Prefer these over ",{"type":52,"tag":68,"props":3255,"children":3257},{"className":3256},[],[3258],{"type":57,"value":3259},"elastic\u002Fworkflows",{"type":57,"value":3261}," when verifying schema-valid YAML.",{"type":52,"tag":53,"props":3263,"children":3264},{},[3265,3270,3272,3278,3280,3286],{"type":52,"tag":60,"props":3266,"children":3267},{},[3268],{"type":57,"value":3269},"Note:",{"type":57,"value":3271}," ",{"type":52,"tag":68,"props":3273,"children":3275},{"className":3274},[],[3276],{"type":57,"value":3277},"x-pack\u002Fplatform\u002Fplugins\u002Fshared\u002Fworkflows\u002F",{"type":57,"value":3279}," is a legacy path — use the ",{"type":52,"tag":68,"props":3281,"children":3283},{"className":3282},[],[3284],{"type":57,"value":3285},"src\u002Fplatform\u002F",{"type":57,"value":3287}," layout above.",{"type":52,"tag":538,"props":3289,"children":3291},{"id":3290},"existing-docs-content-files",[3292],{"type":57,"value":3293},"Existing docs-content files",{"type":52,"tag":53,"props":3295,"children":3296},{},[3297],{"type":57,"value":3298},"If a docs-content checkout exists in the workspace:",{"type":52,"tag":116,"props":3300,"children":3301},{},[3302,3314,3327],{"type":52,"tag":120,"props":3303,"children":3304},{},[3305,3307,3312],{"type":57,"value":3306},"Read sibling pages under ",{"type":52,"tag":68,"props":3308,"children":3310},{"className":3309},[],[3311],{"type":57,"value":73},{"type":57,"value":3313}," for voice, structure, and cross-links",{"type":52,"tag":120,"props":3315,"children":3316},{},[3317,3319,3325],{"type":57,"value":3318},"Check ",{"type":52,"tag":68,"props":3320,"children":3322},{"className":3321},[],[3323],{"type":57,"value":3324},"explore-analyze\u002Fworkflows\u002F_snippets\u002F",{"type":57,"value":3326}," for reusable includes",{"type":52,"tag":120,"props":3328,"children":3329},{},[3330,3331,3337,3339],{"type":57,"value":3318},{"type":52,"tag":68,"props":3332,"children":3334},{"className":3333},[],[3335],{"type":57,"value":3336},"toc.yml",{"type":57,"value":3338}," for navigation placement and whether the target is a hub page with ",{"type":52,"tag":68,"props":3340,"children":3342},{"className":3341},[],[3343],{"type":57,"value":3344},"children:",{"type":52,"tag":538,"props":3346,"children":3348},{"id":3347},"example-workflows",[3349],{"type":57,"value":3350},"Example workflows",{"type":52,"tag":53,"props":3352,"children":3353},{},[3354,3356,3361],{"type":57,"value":3355},"The ",{"type":52,"tag":68,"props":3357,"children":3359},{"className":3358},[],[3360],{"type":57,"value":3259},{"type":57,"value":3362}," library contains example YAML. Use it for realistic examples, but verify each step type and parameter against source before documenting.",{"type":52,"tag":77,"props":3364,"children":3366},{"id":3365},"step-3-apply-workflows-authoring-rules",[3367],{"type":57,"value":3368},"Step 3: Apply Workflows authoring rules",{"type":52,"tag":53,"props":3370,"children":3371},{},[3372,3374,3380],{"type":57,"value":3373},"These conventions are non-negotiable. The ",{"type":52,"tag":344,"props":3375,"children":3377},{"href":41,"rel":3376},[347],[3378],{"type":57,"value":3379},"cheat sheet",{"type":57,"value":3381}," is the authority for gotchas.",{"type":52,"tag":538,"props":3383,"children":3385},{"id":3384},"yaml-examples",[3386],{"type":57,"value":3387},"YAML examples",{"type":52,"tag":116,"props":3389,"children":3390},{},[3391,3404,3409,3429],{"type":52,"tag":120,"props":3392,"children":3393},{},[3394,3396,3402],{"type":57,"value":3395},"Use ",{"type":52,"tag":68,"props":3397,"children":3399},{"className":3398},[],[3400],{"type":57,"value":3401},"steps:",{"type":57,"value":3403}," blocks for step-focused examples; include full workflow YAML only when triggers, inputs, or settings matter",{"type":52,"tag":120,"props":3405,"children":3406},{},[3407],{"type":57,"value":3408},"Indent with two spaces; keep examples copy-pasteable",{"type":52,"tag":120,"props":3410,"children":3411},{},[3412,3414,3420,3422,3428],{"type":57,"value":3413},"Name steps descriptively (",{"type":52,"tag":68,"props":3415,"children":3417},{"className":3416},[],[3418],{"type":57,"value":3419},"search_for_alerts",{"type":57,"value":3421},", not ",{"type":52,"tag":68,"props":3423,"children":3425},{"className":3424},[],[3426],{"type":57,"value":3427},"step1",{"type":57,"value":2937},{"type":52,"tag":120,"props":3430,"children":3431},{},[3432,3434,3440],{"type":57,"value":3433},"Show data flow between steps explicitly (",{"type":52,"tag":68,"props":3435,"children":3437},{"className":3436},[],[3438],{"type":57,"value":3439},"steps.\u003Cname>.output",{"type":57,"value":2937},{"type":52,"tag":538,"props":3442,"children":3444},{"id":3443},"syntax-rules",[3445],{"type":57,"value":3446},"Syntax rules",{"type":52,"tag":361,"props":3448,"children":3449},{},[3450,3471],{"type":52,"tag":365,"props":3451,"children":3452},{},[3453],{"type":52,"tag":369,"props":3454,"children":3455},{},[3456,3461,3466],{"type":52,"tag":373,"props":3457,"children":3458},{},[3459],{"type":57,"value":3460},"Rule",{"type":52,"tag":373,"props":3462,"children":3463},{},[3464],{"type":57,"value":3465},"Correct",{"type":52,"tag":373,"props":3467,"children":3468},{},[3469],{"type":57,"value":3470},"Wrong",{"type":52,"tag":389,"props":3472,"children":3473},{},[3474,3500,3522,3567,3604,3654,3681,3722,3757,3787],{"type":52,"tag":369,"props":3475,"children":3476},{},[3477,3482,3491],{"type":52,"tag":396,"props":3478,"children":3479},{},[3480],{"type":57,"value":3481},"Arrays\u002Fobjects in Liquid",{"type":52,"tag":396,"props":3483,"children":3484},{},[3485],{"type":52,"tag":68,"props":3486,"children":3488},{"className":3487},[],[3489],{"type":57,"value":3490},"\"${{ event.alerts }}\"",{"type":52,"tag":396,"props":3492,"children":3493},{},[3494],{"type":52,"tag":68,"props":3495,"children":3497},{"className":3496},[],[3498],{"type":57,"value":3499},"\"{{ event.alerts }}\"",{"type":52,"tag":369,"props":3501,"children":3502},{},[3503,3508,3517],{"type":52,"tag":396,"props":3504,"children":3505},{},[3506],{"type":57,"value":3507},"Strings in Liquid",{"type":52,"tag":396,"props":3509,"children":3510},{},[3511],{"type":52,"tag":68,"props":3512,"children":3514},{"className":3513},[],[3515],{"type":57,"value":3516},"\"{{ inputs.name }}\"",{"type":52,"tag":396,"props":3518,"children":3519},{},[3520],{"type":57,"value":3521},"—",{"type":52,"tag":369,"props":3523,"children":3524},{},[3525,3543,3554],{"type":52,"tag":396,"props":3526,"children":3527},{},[3528,3534,3535,3541],{"type":52,"tag":68,"props":3529,"children":3531},{"className":3530},[],[3532],{"type":57,"value":3533},"data.filter",{"type":57,"value":585},{"type":52,"tag":68,"props":3536,"children":3538},{"className":3537},[],[3539],{"type":57,"value":3540},"if",{"type":57,"value":3542}," conditions",{"type":52,"tag":396,"props":3544,"children":3545},{},[3546,3548],{"type":57,"value":3547},"KQL: ",{"type":52,"tag":68,"props":3549,"children":3551},{"className":3550},[],[3552],{"type":57,"value":3553},"item._source.severity : 'critical'",{"type":52,"tag":396,"props":3555,"children":3556},{},[3557,3559,3565],{"type":57,"value":3558},"Liquid: ",{"type":52,"tag":68,"props":3560,"children":3562},{"className":3561},[],[3563],{"type":57,"value":3564},"==",{"type":57,"value":3566}," comparisons",{"type":52,"tag":369,"props":3568,"children":3569},{},[3570,3575,3593],{"type":52,"tag":396,"props":3571,"children":3572},{},[3573],{"type":57,"value":3574},"Cases step parameters",{"type":52,"tag":396,"props":3576,"children":3577},{},[3578,3584,3585,3591],{"type":52,"tag":68,"props":3579,"children":3581},{"className":3580},[],[3582],{"type":57,"value":3583},"case_id",{"type":57,"value":693},{"type":52,"tag":68,"props":3586,"children":3588},{"className":3587},[],[3589],{"type":57,"value":3590},"comment",{"type":57,"value":3592}," (snake_case)",{"type":52,"tag":396,"props":3594,"children":3595},{},[3596,3602],{"type":52,"tag":68,"props":3597,"children":3599},{"className":3598},[],[3600],{"type":57,"value":3601},"caseId",{"type":57,"value":3603}," (camelCase)",{"type":52,"tag":369,"props":3605,"children":3606},{},[3607,3632,3642],{"type":52,"tag":396,"props":3608,"children":3609},{},[3610,3612,3617,3618,3624,3625,3631],{"type":57,"value":3611},"Namespaced step IDs (",{"type":52,"tag":68,"props":3613,"children":3615},{"className":3614},[],[3616],{"type":57,"value":138},{"type":57,"value":693},{"type":52,"tag":68,"props":3619,"children":3621},{"className":3620},[],[3622],{"type":57,"value":3623},"security.*",{"type":57,"value":693},{"type":52,"tag":68,"props":3626,"children":3628},{"className":3627},[],[3629],{"type":57,"value":3630},"elasticsearch.*",{"type":57,"value":2937},{"type":52,"tag":396,"props":3633,"children":3634},{},[3635,3637],{"type":57,"value":3636},"Lowercase dot notation: ",{"type":52,"tag":68,"props":3638,"children":3640},{"className":3639},[],[3641],{"type":57,"value":3061},{"type":52,"tag":396,"props":3643,"children":3644},{},[3645,3647,3652],{"type":57,"value":3646},"PascalCase (",{"type":52,"tag":68,"props":3648,"children":3650},{"className":3649},[],[3651],{"type":57,"value":290},{"type":57,"value":3653},") unless documenting the legacy step itself",{"type":52,"tag":369,"props":3655,"children":3656},{},[3657,3662,3672],{"type":52,"tag":396,"props":3658,"children":3659},{},[3660],{"type":57,"value":3661},"Alert status steps",{"type":52,"tag":396,"props":3663,"children":3664},{},[3665,3670],{"type":52,"tag":68,"props":3666,"children":3668},{"className":3667},[],[3669],{"type":57,"value":290},{"type":57,"value":3671}," (PascalCase)",{"type":52,"tag":396,"props":3673,"children":3674},{},[3675],{"type":52,"tag":68,"props":3676,"children":3678},{"className":3677},[],[3679],{"type":57,"value":3680},"kibana.set_alerts_status",{"type":52,"tag":369,"props":3682,"children":3683},{},[3684,3689,3709],{"type":52,"tag":396,"props":3685,"children":3686},{},[3687],{"type":57,"value":3688},"AI step identifiers",{"type":52,"tag":396,"props":3690,"children":3691},{},[3692,3694,3700,3701,3707],{"type":57,"value":3693},"Top-level ",{"type":52,"tag":68,"props":3695,"children":3697},{"className":3696},[],[3698],{"type":57,"value":3699},"connector-id",{"type":57,"value":693},{"type":52,"tag":68,"props":3702,"children":3704},{"className":3703},[],[3705],{"type":57,"value":3706},"agent-id",{"type":57,"value":3708}," (literal kebab-case)",{"type":52,"tag":396,"props":3710,"children":3711},{},[3712,3714,3720],{"type":57,"value":3713},"Nested under ",{"type":52,"tag":68,"props":3715,"children":3717},{"className":3716},[],[3718],{"type":57,"value":3719},"with",{"type":57,"value":3721},", or Liquid-templated",{"type":52,"tag":369,"props":3723,"children":3724},{},[3725,3730,3746],{"type":52,"tag":396,"props":3726,"children":3727},{},[3728],{"type":57,"value":3729},"JSON serialization",{"type":52,"tag":396,"props":3731,"children":3732},{},[3733,3739,3740],{"type":52,"tag":68,"props":3734,"children":3736},{"className":3735},[],[3737],{"type":57,"value":3738},"| json",{"type":57,"value":693},{"type":52,"tag":68,"props":3741,"children":3743},{"className":3742},[],[3744],{"type":57,"value":3745},"| json_parse",{"type":52,"tag":396,"props":3747,"children":3748},{},[3749,3755],{"type":52,"tag":68,"props":3750,"children":3752},{"className":3751},[],[3753],{"type":57,"value":3754},"to_json",{"type":57,"value":3756}," (does not exist)",{"type":52,"tag":369,"props":3758,"children":3759},{},[3760,3769,3782],{"type":52,"tag":396,"props":3761,"children":3762},{},[3763],{"type":52,"tag":68,"props":3764,"children":3766},{"className":3765},[],[3767],{"type":57,"value":3768},"switch.cases",{"type":52,"tag":396,"props":3770,"children":3771},{},[3772,3774,3780],{"type":57,"value":3773},"Array of ",{"type":52,"tag":68,"props":3775,"children":3777},{"className":3776},[],[3778],{"type":57,"value":3779},"{ case:, steps: }",{"type":57,"value":3781}," objects",{"type":52,"tag":396,"props":3783,"children":3784},{},[3785],{"type":57,"value":3786},"Map\u002Fobject keyed by case value",{"type":52,"tag":369,"props":3788,"children":3789},{},[3790,3800,3816],{"type":52,"tag":396,"props":3791,"children":3792},{},[3793,3798],{"type":52,"tag":68,"props":3794,"children":3796},{"className":3795},[],[3797],{"type":57,"value":1631},{"type":57,"value":3799}," target",{"type":52,"tag":396,"props":3801,"children":3802},{},[3803,3809,3811],{"type":52,"tag":68,"props":3804,"children":3806},{"className":3805},[],[3807],{"type":57,"value":3808},"workflow-id",{"type":57,"value":3810}," inside ",{"type":52,"tag":68,"props":3812,"children":3814},{"className":3813},[],[3815],{"type":57,"value":3719},{"type":52,"tag":396,"props":3817,"children":3818},{},[3819],{"type":57,"value":3820},"Top-level field",{"type":52,"tag":538,"props":3822,"children":3824},{"id":3823},"version-differences",[3825],{"type":57,"value":3826},"Version differences",{"type":52,"tag":53,"props":3828,"children":3829},{},[3830,3832,3837],{"type":57,"value":3831},"When examples involve ",{"type":52,"tag":68,"props":3833,"children":3835},{"className":3834},[],[3836],{"type":57,"value":236},{"type":57,"value":3838},", show both placements with an applies-switch or tabs:",{"type":52,"tag":116,"props":3840,"children":3841},{},[3842,3858],{"type":52,"tag":120,"props":3843,"children":3844},{},[3845,3850,3852],{"type":52,"tag":60,"props":3846,"children":3847},{},[3848],{"type":57,"value":3849},"Stack 9.4 and earlier",{"type":57,"value":3851},": top-level ",{"type":52,"tag":68,"props":3853,"children":3855},{"className":3854},[],[3856],{"type":57,"value":3857},"inputs:",{"type":52,"tag":120,"props":3859,"children":3860},{},[3861,3866,3868,3873,3875,3881],{"type":52,"tag":60,"props":3862,"children":3863},{},[3864],{"type":57,"value":3865},"Stack 9.5+ and Serverless",{"type":57,"value":3867},": ",{"type":52,"tag":68,"props":3869,"children":3871},{"className":3870},[],[3872],{"type":57,"value":236},{"type":57,"value":3874}," nested under ",{"type":52,"tag":68,"props":3876,"children":3878},{"className":3877},[],[3879],{"type":57,"value":3880},"type: manual",{"type":57,"value":3882}," trigger",{"type":52,"tag":53,"props":3884,"children":3885},{},[3886],{"type":57,"value":3887},"Fetch anatomy.md for the canonical tab markup.",{"type":52,"tag":538,"props":3889,"children":3891},{"id":3890},"lifecycle-and-availability",[3892],{"type":57,"value":3893},"Lifecycle and availability",{"type":52,"tag":53,"props":3895,"children":3896},{},[3897,3899,3904],{"type":57,"value":3898},"Note preview\u002FGA status and ",{"type":52,"tag":68,"props":3900,"children":3902},{"className":3901},[],[3903],{"type":57,"value":1061},{"type":57,"value":3905}," tags when a step or feature is version-gated. For deprecated or renamed steps, triggers, or parameters:",{"type":52,"tag":116,"props":3907,"children":3908},{},[3909,3919,3929,3954],{"type":52,"tag":120,"props":3910,"children":3911},{},[3912,3917],{"type":52,"tag":60,"props":3913,"children":3914},{},[3915],{"type":57,"value":3916},"New content",{"type":57,"value":3918}," documents the current replacement, not the deprecated form",{"type":52,"tag":120,"props":3920,"children":3921},{},[3922,3927],{"type":52,"tag":60,"props":3923,"children":3924},{},[3925],{"type":57,"value":3926},"Migration context",{"type":57,"value":3928}," — if you show a deprecated form, mark it deprecated inline and link to the replacement reference",{"type":52,"tag":120,"props":3930,"children":3931},{},[3932,3937,3939,3944,3946,3952],{"type":52,"tag":60,"props":3933,"children":3934},{},[3935],{"type":57,"value":3936},"Migration guides",{"type":57,"value":3938}," — search the Workflows docset for version-specific migration pages (e.g., 9.3 → 9.4) and link to them; use ",{"type":52,"tag":68,"props":3940,"children":3942},{"className":3941},[],[3943],{"type":57,"value":138},{"type":57,"value":3945}," instead of ",{"type":52,"tag":68,"props":3947,"children":3949},{"className":3948},[],[3950],{"type":57,"value":3951},"kibana.createCase",{"type":57,"value":3953},"-style steps as one example, not the only case",{"type":52,"tag":120,"props":3955,"children":3956},{},[3957,3962,3964,3969,3970,3975,3977,3983,3985,3991,3993,3998],{"type":52,"tag":60,"props":3958,"children":3959},{},[3960],{"type":57,"value":3961},"Preferred namespace",{"type":57,"value":3963}," — when new namespaced steps (",{"type":52,"tag":68,"props":3965,"children":3967},{"className":3966},[],[3968],{"type":57,"value":3623},{"type":57,"value":693},{"type":52,"tag":68,"props":3971,"children":3973},{"className":3972},[],[3974],{"type":57,"value":138},{"type":57,"value":3976},") overlap legacy ",{"type":52,"tag":68,"props":3978,"children":3980},{"className":3979},[],[3981],{"type":57,"value":3982},"kibana.*",{"type":57,"value":3984}," PascalCase steps, document the namespaced steps as the preferred path for new workflows and add a cross-reference on the older page (mirror how ",{"type":52,"tag":68,"props":3986,"children":3988},{"className":3987},[],[3989],{"type":57,"value":3990},"kibana.md",{"type":57,"value":3992}," points to ",{"type":52,"tag":68,"props":3994,"children":3996},{"className":3995},[],[3997],{"type":57,"value":138},{"type":57,"value":2937},{"type":52,"tag":77,"props":4000,"children":4002},{"id":4001},"step-4-draft-the-page",[4003],{"type":57,"value":4004},"Step 4: Draft the page",{"type":52,"tag":53,"props":4006,"children":4007},{},[4008,4010,4015,4017,4022],{"type":57,"value":4009},"When a doc issue was provided, draft content that ",{"type":52,"tag":60,"props":4011,"children":4012},{},[4013],{"type":57,"value":4014},"addresses every item",{"type":57,"value":4016}," in ",{"type":52,"tag":68,"props":4018,"children":4020},{"className":4019},[],[4021],{"type":57,"value":1112},{"type":57,"value":4023}," unless explicitly deferred. Map each suggestion to a section, example, or follow-up edit in the draft.",{"type":52,"tag":53,"props":4025,"children":4026},{},[4027],{"type":57,"value":4028},"Follow the page-type structure in the sections below. H1 patterns, opening paragraphs, and section order are defined there.",{"type":52,"tag":53,"props":4030,"children":4031},{},[4032],{"type":57,"value":4033},"Workflows pages use a small set of MyST directives — apply these directly:",{"type":52,"tag":116,"props":4035,"children":4036},{},[4037,4069,4086],{"type":52,"tag":120,"props":4038,"children":4039},{},[4040,4045,4046,4052,4054,4059,4061,4067],{"type":52,"tag":60,"props":4041,"children":4042},{},[4043],{"type":57,"value":4044},"Version splits",{"type":57,"value":719},{"type":52,"tag":68,"props":4047,"children":4049},{"className":4048},[],[4050],{"type":57,"value":4051},"applies-switch",{"type":57,"value":4053}," or tabs for YAML that differs by stack\u002Fserverless version (especially ",{"type":52,"tag":68,"props":4055,"children":4057},{"className":4056},[],[4058],{"type":57,"value":236},{"type":57,"value":4060}," placement). Copy markup from ",{"type":52,"tag":68,"props":4062,"children":4064},{"className":4063},[],[4065],{"type":57,"value":4066},"anatomy.md",{"type":57,"value":4068},"; do not invent tab syntax.",{"type":52,"tag":120,"props":4070,"children":4071},{},[4072,4077,4078,4084],{"type":52,"tag":60,"props":4073,"children":4074},{},[4075],{"type":57,"value":4076},"UI walkthroughs",{"type":57,"value":719},{"type":52,"tag":68,"props":4079,"children":4081},{"className":4080},[],[4082],{"type":57,"value":4083},"stepper",{"type":57,"value":4085}," in authoring-technique pages only.",{"type":52,"tag":120,"props":4087,"children":4088},{},[4089,4094,4095,4101,4103,4108],{"type":52,"tag":60,"props":4090,"children":4091},{},[4092],{"type":57,"value":4093},"Snippets",{"type":57,"value":719},{"type":52,"tag":68,"props":4096,"children":4098},{"className":4097},[],[4099],{"type":57,"value":4100},":::{include}",{"type":57,"value":4102}," from ",{"type":52,"tag":68,"props":4104,"children":4106},{"className":4105},[],[4107],{"type":57,"value":3324},{"type":57,"value":4109}," when a matching snippet exists.",{"type":52,"tag":53,"props":4111,"children":4112},{},[4113,4115,4124],{"type":57,"value":4114},"Consult ",{"type":52,"tag":344,"props":4116,"children":4118},{"href":485,"rel":4117},[347],[4119],{"type":52,"tag":68,"props":4120,"children":4122},{"className":4121},[],[4123],{"type":57,"value":481},{"type":57,"value":4125}," only for a directive you cannot resolve from sibling Workflows pages — skip if not installed.",{"type":52,"tag":538,"props":4127,"children":4129},{"id":4128},"frontmatter",[4130],{"type":57,"value":4131},"Frontmatter",{"type":52,"tag":819,"props":4133,"children":4137},{"className":4134,"code":4135,"language":4136,"meta":824,"style":824},"language-yaml shiki shiki-themes material-theme-lighter material-theme material-theme-palenight","---\nnavigation_title: \u003CShort nav label>   # omit on hub pages when title suffices\ndescription: \u003COne sentence for search and tooltips — include \"workflow\" and the specific topic>\nproducts:\n  - id: kibana\n  - id: cloud-serverless    # include when feature is available on serverless\napplies_to:\n  stack: ga 9.4+            # adjust per feature availability\n  serverless: ga\n---\n","yaml",[4138],{"type":52,"tag":68,"props":4139,"children":4140},{"__ignoreMap":824},[4141,4149,4172,4189,4202,4224,4249,4260,4282,4299],{"type":52,"tag":830,"props":4142,"children":4143},{"class":832,"line":833},[4144],{"type":52,"tag":830,"props":4145,"children":4146},{"style":837},[4147],{"type":57,"value":4148},"---\n",{"type":52,"tag":830,"props":4150,"children":4151},{"class":832,"line":896},[4152,4158,4162,4167],{"type":52,"tag":830,"props":4153,"children":4155},{"style":4154},"--shiki-light:#E53935;--shiki-default:#F07178;--shiki-dark:#F07178",[4156],{"type":57,"value":4157},"navigation_title",{"type":52,"tag":830,"props":4159,"children":4160},{"style":854},[4161],{"type":57,"value":563},{"type":52,"tag":830,"props":4163,"children":4164},{"style":843},[4165],{"type":57,"value":4166}," \u003CShort nav label>",{"type":52,"tag":830,"props":4168,"children":4169},{"style":900},[4170],{"type":57,"value":4171},"   # omit on hub pages when title suffices\n",{"type":52,"tag":830,"props":4173,"children":4174},{"class":832,"line":906},[4175,4180,4184],{"type":52,"tag":830,"props":4176,"children":4177},{"style":4154},[4178],{"type":57,"value":4179},"description",{"type":52,"tag":830,"props":4181,"children":4182},{"style":854},[4183],{"type":57,"value":563},{"type":52,"tag":830,"props":4185,"children":4186},{"style":843},[4187],{"type":57,"value":4188}," \u003COne sentence for search and tooltips — include \"workflow\" and the specific topic>\n",{"type":52,"tag":830,"props":4190,"children":4191},{"class":832,"line":1602},[4192,4197],{"type":52,"tag":830,"props":4193,"children":4194},{"style":4154},[4195],{"type":57,"value":4196},"products",{"type":52,"tag":830,"props":4198,"children":4199},{"style":854},[4200],{"type":57,"value":4201},":\n",{"type":52,"tag":830,"props":4203,"children":4204},{"class":832,"line":1656},[4205,4210,4215,4219],{"type":52,"tag":830,"props":4206,"children":4207},{"style":854},[4208],{"type":57,"value":4209},"  -",{"type":52,"tag":830,"props":4211,"children":4212},{"style":4154},[4213],{"type":57,"value":4214}," id",{"type":52,"tag":830,"props":4216,"children":4217},{"style":854},[4218],{"type":57,"value":563},{"type":52,"tag":830,"props":4220,"children":4221},{"style":843},[4222],{"type":57,"value":4223}," kibana\n",{"type":52,"tag":830,"props":4225,"children":4226},{"class":832,"line":1691},[4227,4231,4235,4239,4244],{"type":52,"tag":830,"props":4228,"children":4229},{"style":854},[4230],{"type":57,"value":4209},{"type":52,"tag":830,"props":4232,"children":4233},{"style":4154},[4234],{"type":57,"value":4214},{"type":52,"tag":830,"props":4236,"children":4237},{"style":854},[4238],{"type":57,"value":563},{"type":52,"tag":830,"props":4240,"children":4241},{"style":843},[4242],{"type":57,"value":4243}," cloud-serverless",{"type":52,"tag":830,"props":4245,"children":4246},{"style":900},[4247],{"type":57,"value":4248},"    # include when feature is available on serverless\n",{"type":52,"tag":830,"props":4250,"children":4251},{"class":832,"line":2033},[4252,4256],{"type":52,"tag":830,"props":4253,"children":4254},{"style":4154},[4255],{"type":57,"value":1061},{"type":52,"tag":830,"props":4257,"children":4258},{"style":854},[4259],{"type":57,"value":4201},{"type":52,"tag":830,"props":4261,"children":4262},{"class":832,"line":2045},[4263,4268,4272,4277],{"type":52,"tag":830,"props":4264,"children":4265},{"style":4154},[4266],{"type":57,"value":4267},"  stack",{"type":52,"tag":830,"props":4269,"children":4270},{"style":854},[4271],{"type":57,"value":563},{"type":52,"tag":830,"props":4273,"children":4274},{"style":843},[4275],{"type":57,"value":4276}," ga 9.4+",{"type":52,"tag":830,"props":4278,"children":4279},{"style":900},[4280],{"type":57,"value":4281},"            # adjust per feature availability\n",{"type":52,"tag":830,"props":4283,"children":4284},{"class":832,"line":23},[4285,4290,4294],{"type":52,"tag":830,"props":4286,"children":4287},{"style":4154},[4288],{"type":57,"value":4289},"  serverless",{"type":52,"tag":830,"props":4291,"children":4292},{"style":854},[4293],{"type":57,"value":563},{"type":52,"tag":830,"props":4295,"children":4296},{"style":843},[4297],{"type":57,"value":4298}," ga\n",{"type":52,"tag":830,"props":4300,"children":4301},{"class":832,"line":2084},[4302],{"type":52,"tag":830,"props":4303,"children":4304},{"style":837},[4305],{"type":57,"value":4148},{"type":52,"tag":53,"props":4307,"children":4308},{},[4309,4311,4317,4318,4324],{"type":57,"value":4310},"Add ",{"type":52,"tag":68,"props":4312,"children":4314},{"className":4313},[],[4315],{"type":57,"value":4316},"type: how-to",{"type":57,"value":675},{"type":52,"tag":68,"props":4319,"children":4321},{"className":4320},[],[4322],{"type":57,"value":4323},"type: tutorial",{"type":57,"value":4325}," when the content type guidelines require it.",{"type":52,"tag":538,"props":4327,"children":4329},{"id":4328},"step-reference-pages",[4330],{"type":57,"value":4331},"Step reference pages",{"type":52,"tag":53,"props":4333,"children":4334},{},[4335,4340,4341,4347,4349,4355],{"type":52,"tag":60,"props":4336,"children":4337},{},[4338],{"type":57,"value":4339},"File",{"type":57,"value":3867},{"type":52,"tag":68,"props":4342,"children":4344},{"className":4343},[],[4345],{"type":57,"value":4346},"explore-analyze\u002Fworkflows\u002Fsteps\u002F\u003Ctopic>.md",{"type":57,"value":4348}," (or a subfolder under ",{"type":52,"tag":68,"props":4350,"children":4352},{"className":4351},[],[4353],{"type":57,"value":4354},"steps\u002F",{"type":57,"value":2937},{"type":52,"tag":53,"props":4357,"children":4358},{},[4359],{"type":57,"value":4360},"When the issue says to model on an existing step page (e.g., Cases action steps), read that sibling page first and mirror its layout rather than inventing a new structure.",{"type":52,"tag":53,"props":4362,"children":4363},{},[4364,4369,4371,4376,4377,4383,4384,4389],{"type":52,"tag":60,"props":4365,"children":4366},{},[4367],{"type":57,"value":4368},"Namespace \u002F action-step family pages",{"type":57,"value":4370}," (e.g., ",{"type":52,"tag":68,"props":4372,"children":4374},{"className":4373},[],[4375],{"type":57,"value":1320},{"type":57,"value":693},{"type":52,"tag":68,"props":4378,"children":4380},{"className":4379},[],[4381],{"type":57,"value":4382},"security.md",{"type":57,"value":693},{"type":52,"tag":68,"props":4385,"children":4387},{"className":4386},[],[4388],{"type":57,"value":3990},{"type":57,"value":4390},") use this structure:",{"type":52,"tag":204,"props":4392,"children":4393},{},[4394,4418,4436,4512,4522,4556,4569],{"type":52,"tag":120,"props":4395,"children":4396},{},[4397,4402,4404,4409,4411,4417],{"type":52,"tag":60,"props":4398,"children":4399},{},[4400],{"type":57,"value":4401},"H1 + anchor",{"type":57,"value":4403}," — name the step family (e.g., \"Security Triage and Investigation action steps\"); set ",{"type":52,"tag":68,"props":4405,"children":4407},{"className":4406},[],[4408],{"type":57,"value":4157},{"type":57,"value":4410}," shorter (e.g., ",{"type":52,"tag":68,"props":4412,"children":4414},{"className":4413},[],[4415],{"type":57,"value":4416},"Security",{"type":57,"value":2937},{"type":52,"tag":120,"props":4419,"children":4420},{},[4421,4426,4428,4434],{"type":52,"tag":60,"props":4422,"children":4423},{},[4424],{"type":57,"value":4425},"Introduction",{"type":57,"value":4427}," — what the ",{"type":52,"tag":68,"props":4429,"children":4431},{"className":4430},[],[4432],{"type":57,"value":4433},"namespace.*",{"type":57,"value":4435}," steps do, when to use them, and how they relate to overlapping steps on other pages",{"type":52,"tag":120,"props":4437,"children":4438},{},[4439,4443,4445],{"type":52,"tag":60,"props":4440,"children":4441},{},[4442],{"type":57,"value":1362},{"type":57,"value":4444}," — namespace-wide rules before per-step detail:\n",{"type":52,"tag":116,"props":4446,"children":4447},{},[4448,4458,4463,4468,4473],{"type":52,"tag":120,"props":4449,"children":4450},{},[4451,4453],{"type":57,"value":4452},"Parameters under ",{"type":52,"tag":68,"props":4454,"children":4456},{"className":4455},[],[4457],{"type":57,"value":3719},{"type":52,"tag":120,"props":4459,"children":4460},{},[4461],{"type":57,"value":4462},"Single vs bulk ID fields",{"type":52,"tag":120,"props":4464,"children":4465},{},[4466],{"type":57,"value":4467},"Add\u002Fremove semantics (preserve existing values; not full replace) when applicable",{"type":52,"tag":120,"props":4469,"children":4470},{},[4471],{"type":57,"value":4472},"Required-field rules (e.g., \"at least one of add\u002Fremove\")",{"type":52,"tag":120,"props":4474,"children":4475},{},[4476,4478,4483,4484,4490,4491,4497,4498,4504,4505,4511],{"type":57,"value":4477},"Parameter naming differences across related step groups — ",{"type":52,"tag":60,"props":4479,"children":4480},{},[4481],{"type":57,"value":4482},"document exactly as implemented; do not normalize",{"type":57,"value":4370},{"type":52,"tag":68,"props":4485,"children":4487},{"className":4486},[],[4488],{"type":57,"value":4489},"alert_ids",{"type":57,"value":1297},{"type":52,"tag":68,"props":4492,"children":4494},{"className":4493},[],[4495],{"type":57,"value":4496},"ids",{"type":57,"value":693},{"type":52,"tag":68,"props":4499,"children":4501},{"className":4500},[],[4502],{"type":57,"value":4503},"close_reason",{"type":57,"value":1297},{"type":52,"tag":68,"props":4506,"children":4508},{"className":4507},[],[4509],{"type":57,"value":4510},"reason",{"type":57,"value":2937},{"type":52,"tag":120,"props":4513,"children":4514},{},[4515,4520],{"type":52,"tag":60,"props":4516,"children":4517},{},[4518],{"type":57,"value":4519},"Step catalog",{"type":57,"value":4521}," — jump links to each step, grouped by subdomain when helpful (e.g., Alerts vs Attacks)",{"type":52,"tag":120,"props":4523,"children":4524},{},[4525,4530,4532],{"type":52,"tag":60,"props":4526,"children":4527},{},[4528],{"type":57,"value":4529},"Per-step sections",{"type":57,"value":4531}," — for each step type:\n",{"type":52,"tag":116,"props":4533,"children":4534},{},[4535,4540,4551],{"type":52,"tag":120,"props":4536,"children":4537},{},[4538],{"type":57,"value":4539},"One-sentence purpose",{"type":52,"tag":120,"props":4541,"children":4542},{},[4543,4545],{"type":57,"value":4544},"Parameter table: ",{"type":52,"tag":68,"props":4546,"children":4548},{"className":4547},[],[4549],{"type":57,"value":4550},"Parameter | Location | Type | Required | Description",{"type":52,"tag":120,"props":4552,"children":4553},{},[4554],{"type":57,"value":4555},"YAML example",{"type":52,"tag":120,"props":4557,"children":4558},{},[4559,4561,4567],{"type":57,"value":4560},"Include ",{"type":52,"tag":68,"props":4562,"children":4564},{"className":4563},[],[4565],{"type":57,"value":4566},":::{include} ..\u002F_snippets\u002Fschema-location-legend.md :::",{"type":57,"value":4568}," when the mirror page uses it",{"type":52,"tag":120,"props":4570,"children":4571},{},[4572,4577],{"type":52,"tag":60,"props":4573,"children":4574},{},[4575],{"type":57,"value":4576},"Related",{"type":57,"value":4578}," — sibling step pages, triggers, step type index, cheat sheet",{"type":52,"tag":53,"props":4580,"children":4581},{},[4582,4587],{"type":52,"tag":60,"props":4583,"children":4584},{},[4585],{"type":57,"value":4586},"Other step reference pages",{"type":57,"value":4588}," may also use:",{"type":52,"tag":116,"props":4590,"children":4591},{},[4592,4602,4612],{"type":52,"tag":120,"props":4593,"children":4594},{},[4595,4600],{"type":52,"tag":60,"props":4596,"children":4597},{},[4598],{"type":57,"value":4599},"Overview table",{"type":57,"value":4601}," — step type → API\u002Foperation mapping",{"type":52,"tag":120,"props":4603,"children":4604},{},[4605,4610],{"type":52,"tag":60,"props":4606,"children":4607},{},[4608],{"type":57,"value":4609},"Combine actions",{"type":57,"value":4611}," — multi-step example showing data flow (search → foreach → action)",{"type":52,"tag":120,"props":4613,"children":4614},{},[4615,4620],{"type":52,"tag":60,"props":4616,"children":4617},{},[4618],{"type":57,"value":4619},"Key concepts",{"type":57,"value":4621}," — output paths, loop variables, field reads for composition (e.g., reading alert fields before an assign step)",{"type":52,"tag":53,"props":4623,"children":4624},{},[4625,4627,4632],{"type":57,"value":4626},"For a ",{"type":52,"tag":60,"props":4628,"children":4629},{},[4630],{"type":57,"value":4631},"single step type",{"type":57,"value":4633}," addition to an existing namespace page, document:",{"type":52,"tag":116,"props":4635,"children":4636},{},[4637,4649,4679,4690,4695],{"type":52,"tag":120,"props":4638,"children":4639},{},[4640,4642,4647],{"type":57,"value":4641},"Required and optional ",{"type":52,"tag":68,"props":4643,"children":4645},{"className":4644},[],[4646],{"type":57,"value":3719},{"type":57,"value":4648}," parameters (table format above)",{"type":52,"tag":120,"props":4650,"children":4651},{},[4652,4654,4659,4660,4665,4666,4671,4672,4678],{"type":57,"value":4653},"Top-level fields (",{"type":52,"tag":68,"props":4655,"children":4657},{"className":4656},[],[4658],{"type":57,"value":3699},{"type":57,"value":693},{"type":52,"tag":68,"props":4661,"children":4663},{"className":4662},[],[4664],{"type":57,"value":3540},{"type":57,"value":693},{"type":52,"tag":68,"props":4667,"children":4669},{"className":4668},[],[4670],{"type":57,"value":2935},{"type":57,"value":693},{"type":52,"tag":68,"props":4673,"children":4675},{"className":4674},[],[4676],{"type":57,"value":4677},"on-failure",{"type":57,"value":3081},{"type":52,"tag":120,"props":4680,"children":4681},{},[4682,4684,4689],{"type":57,"value":4683},"Output shape (",{"type":52,"tag":68,"props":4685,"children":4687},{"className":4686},[],[4688],{"type":57,"value":3439},{"type":57,"value":2937},{"type":52,"tag":120,"props":4691,"children":4692},{},[4693],{"type":57,"value":4694},"One minimal example and one realistic multi-step example when helpful",{"type":52,"tag":120,"props":4696,"children":4697},{},[4698],{"type":57,"value":4699},"Gotchas specific to that step",{"type":52,"tag":53,"props":4701,"children":4702},{},[4703],{"type":57,"value":4704},"After drafting a new namespace page or step, list follow-up edits for:",{"type":52,"tag":116,"props":4706,"children":4707},{},[4708,4722,4736,4750],{"type":52,"tag":120,"props":4709,"children":4710},{},[4711,4720],{"type":52,"tag":60,"props":4712,"children":4713},{},[4714],{"type":52,"tag":68,"props":4715,"children":4717},{"className":4716},[],[4718],{"type":57,"value":4719},"steps\u002Faction-steps.md",{"type":57,"value":4721}," — add a category blurb + link when introducing a new step family",{"type":52,"tag":120,"props":4723,"children":4724},{},[4725,4734],{"type":52,"tag":60,"props":4726,"children":4727},{},[4728],{"type":52,"tag":68,"props":4729,"children":4731},{"className":4730},[],[4732],{"type":57,"value":4733},"reference\u002Fstep-types.md",{"type":57,"value":4735}," — add rows for every new step type",{"type":52,"tag":120,"props":4737,"children":4738},{},[4739,4748],{"type":52,"tag":60,"props":4740,"children":4741},{},[4742],{"type":52,"tag":68,"props":4743,"children":4745},{"className":4744},[],[4746],{"type":57,"value":4747},"reference\u002Fcheat-sheet.md",{"type":57,"value":4749}," — add rows or update task-oriented groupings (e.g., \"Manage alerts\", \"Manage attacks\")",{"type":52,"tag":120,"props":4751,"children":4752},{},[4753,4758,4760,4765,4767,4772],{"type":52,"tag":60,"props":4754,"children":4755},{},[4756],{"type":57,"value":4757},"Overlapping sibling pages",{"type":57,"value":4759}," — cross-reference preferred namespace (e.g., ",{"type":52,"tag":68,"props":4761,"children":4763},{"className":4762},[],[4764],{"type":57,"value":3990},{"type":57,"value":4766}," → ",{"type":52,"tag":68,"props":4768,"children":4770},{"className":4769},[],[4771],{"type":57,"value":3623},{"type":57,"value":2937},{"type":52,"tag":538,"props":4774,"children":4776},{"id":4775},"use-case-pages",[4777],{"type":57,"value":4778},"Use case pages",{"type":52,"tag":53,"props":4780,"children":4781},{},[4782,4786,4787],{"type":52,"tag":60,"props":4783,"children":4784},{},[4785],{"type":57,"value":4339},{"type":57,"value":3867},{"type":52,"tag":68,"props":4788,"children":4790},{"className":4789},[],[4791],{"type":57,"value":4792},"explore-analyze\u002Fworkflows\u002Fuse-cases\u002F\u003Cdomain>.md",{"type":52,"tag":53,"props":4794,"children":4795},{},[4796,4801],{"type":52,"tag":60,"props":4797,"children":4798},{},[4799],{"type":57,"value":4800},"Structure",{"type":57,"value":563},{"type":52,"tag":204,"props":4803,"children":4804},{},[4805,4814,4823,4851],{"type":52,"tag":120,"props":4806,"children":4807},{},[4808,4812],{"type":52,"tag":60,"props":4809,"children":4810},{},[4811],{"type":57,"value":4401},{"type":57,"value":4813}," — domain-focused title (e.g., \"Security workflows\")",{"type":52,"tag":120,"props":4815,"children":4816},{},[4817,4821],{"type":52,"tag":60,"props":4818,"children":4819},{},[4820],{"type":57,"value":4425},{"type":57,"value":4822}," — what teams accomplish with workflows in this domain",{"type":52,"tag":120,"props":4824,"children":4825},{},[4826,4831,4833],{"type":52,"tag":60,"props":4827,"children":4828},{},[4829],{"type":57,"value":4830},"Pattern sections",{"type":57,"value":4832}," — group by intent, not by step type:\n",{"type":52,"tag":116,"props":4834,"children":4835},{},[4836,4841,4846],{"type":52,"tag":120,"props":4837,"children":4838},{},[4839],{"type":57,"value":4840},"What you can automate (bullet list of outcomes)",{"type":52,"tag":120,"props":4842,"children":4843},{},[4844],{"type":57,"value":4845},"Typical triggers and step patterns (brief, with links to step\u002Ftrigger reference)",{"type":52,"tag":120,"props":4847,"children":4848},{},[4849],{"type":57,"value":4850},"Pointers to example workflows or templates when they exist",{"type":52,"tag":120,"props":4852,"children":4853},{},[4854,4858],{"type":52,"tag":60,"props":4855,"children":4856},{},[4857],{"type":57,"value":4576},{"type":57,"value":4859}," — links to relevant step references, authoring techniques, and tutorials",{"type":52,"tag":53,"props":4861,"children":4862},{},[4863],{"type":57,"value":4864},"Use case pages are shorter than step references. Link out rather than duplicating parameter tables.",{"type":52,"tag":538,"props":4866,"children":4868},{"id":4867},"authoring-technique-pages-how-tos",[4869],{"type":57,"value":4870},"Authoring technique pages (how-tos)",{"type":52,"tag":53,"props":4872,"children":4873},{},[4874,4878,4879],{"type":52,"tag":60,"props":4875,"children":4876},{},[4877],{"type":57,"value":4339},{"type":57,"value":3867},{"type":52,"tag":68,"props":4880,"children":4882},{"className":4881},[],[4883],{"type":57,"value":4884},"explore-analyze\u002Fworkflows\u002Fauthoring-techniques\u002F\u003Caction-verb-topic>.md",{"type":52,"tag":53,"props":4886,"children":4887},{},[4888,4890,4896],{"type":57,"value":4889},"Follow the ",{"type":52,"tag":344,"props":4891,"children":4893},{"href":44,"rel":4892},[347],[4894],{"type":57,"value":4895},"how-to content type guidelines",{"type":57,"value":563},{"type":52,"tag":204,"props":4898,"children":4899},{},[4900,4910,4919,4928,4945,4955],{"type":52,"tag":120,"props":4901,"children":4902},{},[4903,4908],{"type":52,"tag":60,"props":4904,"children":4905},{},[4906],{"type":57,"value":4907},"Action-verb H1",{"type":57,"value":4909}," — e.g., \"Monitor workflow execution\"",{"type":52,"tag":120,"props":4911,"children":4912},{},[4913,4917],{"type":52,"tag":60,"props":4914,"children":4915},{},[4916],{"type":57,"value":4425},{"type":57,"value":4918}," — outcome the reader will achieve",{"type":52,"tag":120,"props":4920,"children":4921},{},[4922,4926],{"type":52,"tag":60,"props":4923,"children":4924},{},[4925],{"type":57,"value":1380},{"type":57,"value":4927}," — permissions, prerequisites, UI access path",{"type":52,"tag":120,"props":4929,"children":4930},{},[4931,4936,4938,4943],{"type":52,"tag":60,"props":4932,"children":4933},{},[4934],{"type":57,"value":4935},"Numbered steps",{"type":57,"value":4937}," — imperative verbs, one action per step; use ",{"type":52,"tag":68,"props":4939,"children":4941},{"className":4940},[],[4942],{"type":57,"value":4083},{"type":57,"value":4944}," for UI walkthroughs",{"type":52,"tag":120,"props":4946,"children":4947},{},[4948,4953],{"type":52,"tag":60,"props":4949,"children":4950},{},[4951],{"type":57,"value":4952},"Success checkpoints",{"type":57,"value":4954}," — how to confirm each critical step worked",{"type":52,"tag":120,"props":4956,"children":4957},{},[4958,4963,4964],{"type":52,"tag":60,"props":4959,"children":4960},{},[4961],{"type":57,"value":4962},"Next steps",{"type":57,"value":1751},{"type":52,"tag":60,"props":4965,"children":4966},{},[4967],{"type":57,"value":4576},{"type":52,"tag":53,"props":4969,"children":4970},{},[4971],{"type":57,"value":4972},"Keep how-tos to ≤10 steps. Chain into a tutorial if the scope is broader.",{"type":52,"tag":538,"props":4974,"children":4976},{"id":4975},"concept-and-reference-pages",[4977],{"type":57,"value":4978},"Concept and reference pages",{"type":52,"tag":53,"props":4980,"children":4981},{},[4982,4987],{"type":52,"tag":60,"props":4983,"children":4984},{},[4985],{"type":57,"value":4986},"Concepts",{"type":57,"value":4988}," explain triggers, steps, data flow, Liquid, error handling — focus on mental models and links to reference detail.",{"type":52,"tag":53,"props":4990,"children":4991},{},[4992,4997],{"type":52,"tag":60,"props":4993,"children":4994},{},[4995],{"type":57,"value":4996},"Reference pages",{"type":57,"value":4998}," (anatomy, cheat sheet, context variables) use tables, field-by-field descriptions, and version tabs. Prefer tables over prose for parameter catalogs.",{"type":52,"tag":538,"props":5000,"children":5002},{"id":5001},"tutorial-pages",[5003],{"type":57,"value":5004},"Tutorial pages",{"type":52,"tag":53,"props":5006,"children":5007},{},[5008,5012,5013],{"type":52,"tag":60,"props":5009,"children":5010},{},[5011],{"type":57,"value":4339},{"type":57,"value":3867},{"type":52,"tag":68,"props":5014,"children":5016},{"className":5015},[],[5017],{"type":57,"value":5018},"explore-analyze\u002Fworkflows\u002Fget-started\u002F\u003Ctopic>.md",{"type":52,"tag":53,"props":5020,"children":5021},{},[5022],{"type":57,"value":5023},"Follow tutorial content type guidelines. Chain multiple tasks with explanatory context. Include sample data setup, checkpoints, and a \"what you built\" summary.",{"type":52,"tag":77,"props":5025,"children":5027},{"id":5026},"step-5-cross-link-and-navigation",[5028],{"type":57,"value":5029},"Step 5: Cross-link and navigation",{"type":52,"tag":53,"props":5031,"children":5032},{},[5033],{"type":57,"value":5034},"After drafting:",{"type":52,"tag":204,"props":5036,"children":5037},{},[5038,5050,5061,5084,5107,5131,5142],{"type":52,"tag":120,"props":5039,"children":5040},{},[5041,5043,5048],{"type":57,"value":5042},"Add links ",{"type":52,"tag":60,"props":5044,"children":5045},{},[5046],{"type":57,"value":5047},"to",{"type":57,"value":5049}," the new page from hub pages, step type index, cheat sheet, or choose-the-right-step as appropriate",{"type":52,"tag":120,"props":5051,"children":5052},{},[5053,5055,5059],{"type":57,"value":5054},"Add a ",{"type":52,"tag":60,"props":5056,"children":5057},{},[5058],{"type":57,"value":4576},{"type":57,"value":5060}," section at the bottom of the new page (3–5 links)",{"type":52,"tag":120,"props":5062,"children":5063},{},[5064,5066,5074,5076,5082],{"type":57,"value":5065},"Update ",{"type":52,"tag":60,"props":5067,"children":5068},{},[5069],{"type":52,"tag":68,"props":5070,"children":5072},{"className":5071},[],[5073],{"type":57,"value":4719},{"type":57,"value":5075}," when adding a new step family — match existing category blurbs (short description, \"Use … to:\" bullets, ",{"type":52,"tag":68,"props":5077,"children":5079},{"className":5078},[],[5080],{"type":57,"value":5081},"Refer to …",{"type":57,"value":5083}," link)",{"type":52,"tag":120,"props":5085,"children":5086},{},[5087,5088,5096,5097,5105],{"type":57,"value":5065},{"type":52,"tag":60,"props":5089,"children":5090},{},[5091],{"type":52,"tag":68,"props":5092,"children":5094},{"className":5093},[],[5095],{"type":57,"value":4733},{"type":57,"value":1751},{"type":52,"tag":60,"props":5098,"children":5099},{},[5100],{"type":52,"tag":68,"props":5101,"children":5103},{"className":5102},[],[5104],{"type":57,"value":4747},{"type":57,"value":5106}," when the issue lists them as deliverables — do not stop at the primary page draft",{"type":52,"tag":120,"props":5108,"children":5109},{},[5110,5111,5116,5118,5123,5125,5130],{"type":57,"value":4310},{"type":52,"tag":60,"props":5112,"children":5113},{},[5114],{"type":57,"value":5115},"preferred-namespace cross-references",{"type":57,"value":5117}," on overlapping sibling pages (e.g., steer new alert-triage workflows from ",{"type":52,"tag":68,"props":5119,"children":5121},{"className":5120},[],[5122],{"type":57,"value":290},{"type":57,"value":5124}," to ",{"type":52,"tag":68,"props":5126,"children":5128},{"className":5127},[],[5129],{"type":57,"value":3061},{"type":57,"value":2937},{"type":52,"tag":120,"props":5132,"children":5133},{},[5134,5135,5140],{"type":57,"value":5065},{"type":52,"tag":68,"props":5136,"children":5138},{"className":5137},[],[5139],{"type":57,"value":3336},{"type":57,"value":5141}," if adding a new file (confirm placement with the user)",{"type":52,"tag":120,"props":5143,"children":5144},{},[5145],{"type":57,"value":5146},"Remove duplicated content from hub pages — hubs summarize and link, they do not restate reference detail",{"type":52,"tag":77,"props":5148,"children":5150},{"id":5149},"step-6-validate",[5151],{"type":57,"value":5152},"Step 6: Validate",{"type":52,"tag":53,"props":5154,"children":5155},{},[5156],{"type":57,"value":5157},"Before presenting the draft:",{"type":52,"tag":204,"props":5159,"children":5160},{},[5161,5176,5188,5193,5198],{"type":52,"tag":120,"props":5162,"children":5163},{},[5164,5165,5174],{"type":57,"value":2670},{"type":52,"tag":344,"props":5166,"children":5168},{"href":452,"rel":5167},[347],[5169],{"type":52,"tag":68,"props":5170,"children":5172},{"className":5171},[],[5173],{"type":57,"value":447},{"type":57,"value":5175}," on the draft if installed — otherwise spot-check structure against the page-type templates in Step 4",{"type":52,"tag":120,"props":5177,"children":5178},{},[5179,5181,5186],{"type":57,"value":5180},"Validate outbound links — use elastic-docs MCP ",{"type":52,"tag":68,"props":5182,"children":5184},{"className":5183},[],[5185],{"type":57,"value":2753},{"type":57,"value":5187}," (or WebFetch) to resolve each cross-link in the draft when a file path is available",{"type":52,"tag":120,"props":5189,"children":5190},{},[5191],{"type":57,"value":5192},"Spot-check YAML examples against the cheat sheet gotchas list",{"type":52,"tag":120,"props":5194,"children":5195},{},[5196],{"type":57,"value":5197},"Confirm step types and parameter names against Kibana source",{"type":52,"tag":120,"props":5199,"children":5200},{},[5201,5203,5207],{"type":57,"value":5202},"Cross-check the draft against the ",{"type":52,"tag":60,"props":5204,"children":5205},{},[5206],{"type":57,"value":2424},{"type":57,"value":5208}," table — every non-deferred item must be addressed or explained",{"type":52,"tag":53,"props":5210,"children":5211},{},[5212],{"type":57,"value":5213},"Report any items you could not verify against source. Note any companion skills or MCP tools that were unavailable.",{"type":52,"tag":77,"props":5215,"children":5217},{"id":5216},"output-format",[5218],{"type":57,"value":5219},"Output format",{"type":52,"tag":53,"props":5221,"children":5222},{},[5223],{"type":57,"value":5224},"Present:",{"type":52,"tag":204,"props":5226,"children":5227},{},[5228,5244,5254,5264,5274,5284],{"type":52,"tag":120,"props":5229,"children":5230},{},[5231,5236,5238,5242],{"type":52,"tag":60,"props":5232,"children":5233},{},[5234],{"type":57,"value":5235},"Intake summary",{"type":57,"value":5237}," — issue link, scope, ",{"type":52,"tag":60,"props":5239,"children":5240},{},[5241],{"type":57,"value":2424},{"type":57,"value":5243}," (with status per item), resolved and unresolved questions (omit if no issue was used)",{"type":52,"tag":120,"props":5245,"children":5246},{},[5247,5252],{"type":52,"tag":60,"props":5248,"children":5249},{},[5250],{"type":57,"value":5251},"Page classification",{"type":57,"value":5253}," — type, target file path, rationale",{"type":52,"tag":120,"props":5255,"children":5256},{},[5257,5262],{"type":52,"tag":60,"props":5258,"children":5259},{},[5260],{"type":57,"value":5261},"Research summary",{"type":57,"value":5263}," — source pages read, Kibana files consulted",{"type":52,"tag":120,"props":5265,"children":5266},{},[5267,5272],{"type":52,"tag":60,"props":5268,"children":5269},{},[5270],{"type":57,"value":5271},"Draft content",{"type":57,"value":5273}," — full markdown with frontmatter, ready to write to docs-content",{"type":52,"tag":120,"props":5275,"children":5276},{},[5277,5282],{"type":52,"tag":60,"props":5278,"children":5279},{},[5280],{"type":57,"value":5281},"Follow-up edits",{"type":57,"value":5283}," — other files to update (index, toc.yml, hub links); include deferred items from suggested doc work",{"type":52,"tag":120,"props":5285,"children":5286},{},[5287,5291],{"type":52,"tag":60,"props":5288,"children":5289},{},[5290],{"type":57,"value":1185},{"type":57,"value":5292}," — anything still needing SME review after drafting",{"type":52,"tag":53,"props":5294,"children":5295},{},[5296],{"type":57,"value":5297},"If the user provided a file path, write the draft to that path. Otherwise, propose the path and show the content for review first.",{"type":52,"tag":5299,"props":5300,"children":5301},"style",{},[5302],{"type":57,"value":5303},"html .light .shiki span {color: var(--shiki-light);background: var(--shiki-light-bg);font-style: var(--shiki-light-font-style);font-weight: var(--shiki-light-font-weight);text-decoration: var(--shiki-light-text-decoration);}html.light .shiki span {color: var(--shiki-light);background: var(--shiki-light-bg);font-style: var(--shiki-light-font-style);font-weight: var(--shiki-light-font-weight);text-decoration: var(--shiki-light-text-decoration);}html .default .shiki span {color: var(--shiki-default);background: var(--shiki-default-bg);font-style: var(--shiki-default-font-style);font-weight: var(--shiki-default-font-weight);text-decoration: var(--shiki-default-text-decoration);}html .shiki span {color: var(--shiki-default);background: var(--shiki-default-bg);font-style: var(--shiki-default-font-style);font-weight: var(--shiki-default-font-weight);text-decoration: var(--shiki-default-text-decoration);}html .dark .shiki span {color: var(--shiki-dark);background: var(--shiki-dark-bg);font-style: var(--shiki-dark-font-style);font-weight: var(--shiki-dark-font-weight);text-decoration: var(--shiki-dark-text-decoration);}html.dark .shiki span {color: var(--shiki-dark);background: var(--shiki-dark-bg);font-style: var(--shiki-dark-font-style);font-weight: var(--shiki-dark-font-weight);text-decoration: var(--shiki-dark-text-decoration);}",{"items":5305,"total":5379},[5306,5316,5329,5339,5344,5356,5366],{"slug":5307,"name":5307,"fn":5308,"description":5309,"org":5310,"tags":5311,"stars":19,"repoUrl":20,"updatedAt":5315},"docs-applies-to-tagging","validate applies_to tags in Elastic documentation","Validate and generate applies_to tags in Elastic documentation, including for cumulative docs across versions and deployment types. Use when writing new docs pages, reviewing existing pages for correct applies_to usage, deciding whether to preserve or replace existing version-scoped content, or when content changes lifecycle state (experimental, preview, beta, GA, deprecated, removed).",{"slug":8,"name":9,"logoUrl":10,"githubOrg":8},[5312,5313,5314],{"name":13,"slug":14,"type":15},{"name":9,"slug":8,"type":15},{"name":17,"slug":18,"type":15},"2026-07-12T07:50:42.801473",{"slug":5317,"name":5317,"fn":5318,"description":5319,"org":5320,"tags":5321,"stars":19,"repoUrl":20,"updatedAt":5328},"docs-check-style","check documentation for Elastic style compliance","Check documentation for Elastic style guide compliance using Vale linter output and style rules. Use when writing, editing, or reviewing docs to catch voice, tone, grammar, formatting, accessibility, and word choice issues.",{"slug":8,"name":9,"logoUrl":10,"githubOrg":8},[5322,5325,5326,5327],{"name":5323,"slug":5324,"type":15},"Accessibility","accessibility",{"name":13,"slug":14,"type":15},{"name":9,"slug":8,"type":15},{"name":17,"slug":18,"type":15},"2026-07-12T07:49:36.112751",{"slug":5330,"name":5330,"fn":5331,"description":5332,"org":5333,"tags":5334,"stars":19,"repoUrl":20,"updatedAt":5338},"docs-content-type-checker","check Elastic documentation content types","Check a docs-content page against Elastic content type guidelines (overview, how-to, tutorial, troubleshooting, changelog), or classify a proposed page idea against the content types before drafting. Use when the user asks to check content type compliance, validate page structure, review a doc against content type standards, or decide which content type a planned page should use.",{"slug":8,"name":9,"logoUrl":10,"githubOrg":8},[5335,5336,5337],{"name":13,"slug":14,"type":15},{"name":9,"slug":8,"type":15},{"name":17,"slug":18,"type":15},"2026-07-12T07:50:36.826563",{"slug":4,"name":4,"fn":5,"description":6,"org":5340,"tags":5341,"stars":19,"repoUrl":20,"updatedAt":21},{"slug":8,"name":9,"logoUrl":10,"githubOrg":8},[5342,5343],{"name":13,"slug":14,"type":15},{"name":17,"slug":18,"type":15},{"slug":5345,"name":5345,"fn":5346,"description":5347,"org":5348,"tags":5349,"stars":19,"repoUrl":20,"updatedAt":5355},"docs-fix-changelog","improve Elastic changelog YAML files","Suggest improved text for changelog YAML files against current Elastic standards. Mirrors the pattern catalog from docs-review-changelog to provide consistent fixes. Includes type-title alignment checking and technical content assessment to catch overly technical titles that need user-focused rewrites. Features repository-aware area validation and enhanced confidence scoring. Supports single files or directories. Fetches canonical guidance to stay in sync. Use after review identifies quality issues, or when drafting new changelogs.",{"slug":8,"name":9,"logoUrl":10,"githubOrg":8},[5350,5351,5352,5353],{"name":13,"slug":14,"type":15},{"name":9,"slug":8,"type":15},{"name":17,"slug":18,"type":15},{"name":5354,"slug":4136,"type":15},"YAML","2026-07-12T07:48:58.570382",{"slug":5357,"name":5357,"fn":5358,"description":5359,"org":5360,"tags":5361,"stars":19,"repoUrl":20,"updatedAt":5365},"docs-flag-jargon-skill","flag Elastic jargon in documentation","Flag Elastic-internal jargon in documentation and suggest plain-language replacements. Use when reviewing, writing, or editing docs to catch terms that external readers would not understand.",{"slug":8,"name":9,"logoUrl":10,"githubOrg":8},[5362,5363,5364],{"name":13,"slug":14,"type":15},{"name":9,"slug":8,"type":15},{"name":17,"slug":18,"type":15},"2026-07-12T07:49:34.836748",{"slug":5367,"name":5367,"fn":5368,"description":5369,"org":5370,"tags":5371,"stars":19,"repoUrl":20,"updatedAt":5378},"docs-frontmatter-audit","audit Elastic documentation frontmatter","Audit Elastic documentation files for frontmatter completeness and correctness. Checks products, description, and navigation_title fields across a directory. Use when auditing docs metadata, checking frontmatter quality before publishing, or validating a batch of files.",{"slug":8,"name":9,"logoUrl":10,"githubOrg":8},[5372,5375,5376,5377],{"name":5373,"slug":5374,"type":15},"Audit","audit",{"name":13,"slug":14,"type":15},{"name":9,"slug":8,"type":15},{"name":17,"slug":18,"type":15},"2026-07-12T07:49:39.883351",18,{"items":5381,"total":5550},[5382,5401,5418,5433,5452,5464,5474,5488,5500,5513,5524,5537],{"slug":5383,"name":5383,"fn":5384,"description":5385,"org":5386,"tags":5387,"stars":5398,"repoUrl":5399,"updatedAt":5400},"accessing-benchmark-results","retrieve and analyze Rally benchmark results","Retrieve Rally benchmark results from an external Elasticsearch metrics store. Use to list past races, get a single race's overall (per-task) results, chart a metric's trend across multiple runs, compare two races, or check whether a run converged — e.g. \"show me recent geonames races\", \"what's the service_time trend for nyc_taxis over the last 30 days?\", \"compare these two race-ids\". Applies when datastore.type = elasticsearch is set in ~\u002F.rally\u002Frally.ini.",{"slug":8,"name":9,"logoUrl":10,"githubOrg":8},[5388,5391,5394,5395],{"name":5389,"slug":5390,"type":15},"Analytics","analytics",{"name":5392,"slug":5393,"type":15},"Data Analysis","data-analysis",{"name":9,"slug":8,"type":15},{"name":5396,"slug":5397,"type":15},"Performance","performance",2027,"https:\u002F\u002Fgithub.com\u002Felastic\u002Frally","2026-07-12T07:46:38.54144",{"slug":5402,"name":5402,"fn":5403,"description":5404,"org":5405,"tags":5406,"stars":5398,"repoUrl":5399,"updatedAt":5417},"developing-rally","develop and debug Rally source code","Work on Rally's own codebase, not running benchmarks with it. Use when setting up the dev environment, running Rally's tests or linters, navigating its source, debugging Rally's own code, or making changes to Rally itself.",{"slug":8,"name":9,"logoUrl":10,"githubOrg":8},[5407,5410,5411,5414],{"name":5408,"slug":5409,"type":15},"Debugging","debugging",{"name":9,"slug":8,"type":15},{"name":5412,"slug":5413,"type":15},"Engineering","engineering",{"name":5415,"slug":5416,"type":15},"Local Development","local-development","2026-07-12T07:46:35.976807",{"slug":5419,"name":5419,"fn":5420,"description":5421,"org":5422,"tags":5423,"stars":5398,"repoUrl":5399,"updatedAt":5432},"running-benchmarks","run Rally benchmarks against Elasticsearch","Run Rally benchmarks (races) against Elasticsearch — an existing\u002Fexternal cluster or a Rally-provisioned distribution — and read the summary report. Use when running a race (any pipeline, track, challenge, target-hosts, or auth) or when interpreting throughput, latency, and service_time results.",{"slug":8,"name":9,"logoUrl":10,"githubOrg":8},[5424,5425,5428,5429],{"name":9,"slug":8,"type":15},{"name":5426,"slug":5427,"type":15},"Elasticsearch","elasticsearch",{"name":5396,"slug":5397,"type":15},{"name":5430,"slug":5431,"type":15},"Testing","testing","2026-07-12T07:46:37.277964",{"slug":5434,"name":5434,"fn":5435,"description":5436,"org":5437,"tags":5438,"stars":5449,"repoUrl":5450,"updatedAt":5451},"cloud-access-management","manage Elastic Cloud organization access","Manage Elastic Cloud organization access: invite users, assign roles to Serverless projects, and create or revoke Cloud API keys. Use when granting, modifying, or auditing user access.\n",{"slug":8,"name":9,"logoUrl":10,"githubOrg":8},[5439,5442,5443,5446],{"name":5440,"slug":5441,"type":15},"Cloud","cloud",{"name":9,"slug":8,"type":15},{"name":5444,"slug":5445,"type":15},"Operations","operations",{"name":5447,"slug":5448,"type":15},"Permissions","permissions",531,"https:\u002F\u002Fgithub.com\u002Felastic\u002Fagent-skills","2026-07-12T07:46:44.946285",{"slug":5453,"name":5453,"fn":5454,"description":5455,"org":5456,"tags":5457,"stars":5449,"repoUrl":5450,"updatedAt":5463},"cloud-create-project","create Elastic Cloud Serverless projects","Creates Elastic Cloud Serverless projects (Elasticsearch, Observability, or Security) via the REST API, saves credentials to file, and bootstraps a scoped Elasticsearch API key. Use when creating a new serverless project, provisioning a search or observability environment, or spinning up a new Elastic Cloud project.\n",{"slug":8,"name":9,"logoUrl":10,"githubOrg":8},[5458,5459,5462],{"name":5440,"slug":5441,"type":15},{"name":5460,"slug":5461,"type":15},"Deployment","deployment",{"name":5426,"slug":5427,"type":15},"2026-07-12T07:46:42.353362",{"slug":5465,"name":5465,"fn":5466,"description":5467,"org":5468,"tags":5469,"stars":5449,"repoUrl":5450,"updatedAt":5473},"cloud-manage-project","manage Elastic Cloud Serverless projects","Manages existing Elastic Cloud Serverless projects: list, get, update, delete, reset credentials, resume, and load saved credentials. Connects to existing projects by resolving endpoints and acquiring scoped Elasticsearch API keys. Use when performing day-2 operations on serverless projects, connecting to an existing project, loading or resetting project credentials, or looking up project details.\n",{"slug":8,"name":9,"logoUrl":10,"githubOrg":8},[5470,5471,5472],{"name":5440,"slug":5441,"type":15},{"name":5426,"slug":5427,"type":15},{"name":5444,"slug":5445,"type":15},"2026-07-12T07:46:41.097412",{"slug":5475,"name":5475,"fn":5476,"description":5477,"org":5478,"tags":5479,"stars":5449,"repoUrl":5450,"updatedAt":5487},"cloud-network-security","manage Elastic Cloud network security","Manage Serverless network security (traffic filters): create, update, and delete IP filters and AWS PrivateLink VPC filters. Use when restricting network access or configuring private connectivity.\n",{"slug":8,"name":9,"logoUrl":10,"githubOrg":8},[5480,5481,5482,5485],{"name":5440,"slug":5441,"type":15},{"name":5426,"slug":5427,"type":15},{"name":5483,"slug":5484,"type":15},"Networking","networking",{"name":4416,"slug":5486,"type":15},"security","2026-07-12T07:46:43.675992",{"slug":5489,"name":5489,"fn":5490,"description":5491,"org":5492,"tags":5493,"stars":5449,"repoUrl":5450,"updatedAt":5499},"cloud-setup","configure Elastic Cloud authentication","Configures Elastic Cloud authentication and environment defaults. Use when setting up EC_API_KEY, configuring Cloud API access, or when another cloud skill requires credentials.\n",{"slug":8,"name":9,"logoUrl":10,"githubOrg":8},[5494,5497,5498],{"name":5495,"slug":5496,"type":15},"Authentication","authentication",{"name":5440,"slug":5441,"type":15},{"name":5426,"slug":5427,"type":15},"2026-07-12T07:46:39.783105",{"slug":5501,"name":5501,"fn":5502,"description":5503,"org":5504,"tags":5505,"stars":5449,"repoUrl":5450,"updatedAt":5512},"elasticsearch-audit","configure Elasticsearch security audit logs","Enable, configure, and query Elasticsearch security audit logs. Use when the task involves audit logging setup, event filtering, or investigating security incidents like failed logins.\n",{"slug":8,"name":9,"logoUrl":10,"githubOrg":8},[5506,5507,5508,5511],{"name":5373,"slug":5374,"type":15},{"name":5426,"slug":5427,"type":15},{"name":5509,"slug":5510,"type":15},"Logs","logs",{"name":4416,"slug":5486,"type":15},"2026-07-12T07:47:35.092599",{"slug":5514,"name":5514,"fn":5515,"description":5516,"org":5517,"tags":5518,"stars":5449,"repoUrl":5450,"updatedAt":5523},"elasticsearch-authn","configure Elasticsearch authentication realms","Authenticate to Elasticsearch using native, file-based, LDAP\u002FAD, SAML, OIDC, Kerberos, JWT, or certificate realms. Use when connecting with credentials, choosing a realm, or managing API keys. Assumes the target realms are already configured.\n",{"slug":8,"name":9,"logoUrl":10,"githubOrg":8},[5519,5520,5521,5522],{"name":5495,"slug":5496,"type":15},{"name":9,"slug":8,"type":15},{"name":5426,"slug":5427,"type":15},{"name":4416,"slug":5486,"type":15},"2026-07-12T07:47:41.474547",{"slug":5525,"name":5525,"fn":5526,"description":5527,"org":5528,"tags":5529,"stars":5449,"repoUrl":5450,"updatedAt":5536},"elasticsearch-authz","manage Elasticsearch RBAC and security roles","Manage Elasticsearch RBAC: native users, roles, role mappings, document- and field-level security. Use when creating users or roles, assigning privileges, or mapping external realms like LDAP\u002FSAML.\n",{"slug":8,"name":9,"logoUrl":10,"githubOrg":8},[5530,5531,5532,5535],{"name":9,"slug":8,"type":15},{"name":5426,"slug":5427,"type":15},{"name":5533,"slug":5534,"type":15},"RBAC","rbac",{"name":4416,"slug":5486,"type":15},"2026-07-12T07:47:36.394177",{"slug":5538,"name":5538,"fn":5539,"description":5540,"org":5541,"tags":5542,"stars":5449,"repoUrl":5450,"updatedAt":5549},"elasticsearch-esql","query Elasticsearch data with ES|QL","Execute ES|QL (Elasticsearch Query Language) queries, use when the user wants to query Elasticsearch data, analyze logs, aggregate metrics, explore data, or create charts and dashboards from ES|QL results.\n",{"slug":8,"name":9,"logoUrl":10,"githubOrg":8},[5543,5544,5545,5546],{"name":5389,"slug":5390,"type":15},{"name":5392,"slug":5393,"type":15},{"name":5426,"slug":5427,"type":15},{"name":5547,"slug":5548,"type":15},"SQL","sql","2026-07-12T07:47:40.249533",86]