Elastic Security v9.4 introduces Entity Analytics Watchlists, a feature that lets security teams create named, weighted lists of users, hosts, and services to inject organizational context directly into the platform's risk scoring pipeline. Unlike traditional SIEM approaches that rely on behavioral anomalies or threat intel, Watchlists codify institutional knowledge — departing employees, privileged admins, critical infrastructure — as first-class risk signals without requiring ES|QL, pipeline configuration, or detection engineering. Entities on multiple watchlists compound their risk scores alongside alert activity and asset criticality, surfacing the highest-risk entities with full context for analysts. Lists can also be auto-populated via API integrations (e.g., HR systems) to stay current without manual upkeep.