Allow root admins to delegate login policy management to space admins

We would like Spacelift to support optional delegation of login policy management to space admins.

In larger organisations, login policy ownership often needs to sit closer to the teams who own and operate individual spaces. This is especially important where spaces are created dynamically through Terraform, or where child spaces are managed independently and root admins do not have enough context or visibility to manage every login policy centrally.

The current model requires root admins to manage login policies for all spaces. That creates an operational bottleneck, slows down onboarding, and makes it harder to scale Spacelift across multiple teams, business units, or platform domains.

Ideally, root admins should be able to decide whether login policy management can be delegated on a per-space basis. Delegated space admins should only be able to manage login policies within their own space, or within explicitly permitted child spaces, without affecting the root space or sibling spaces.

Root admins should retain central control, visibility, and the ability to revoke delegation if needed.

Workaround
None
Problem
Login policies can only be managed centrally by root admins. There is currently no way to delegate login policy management to space owners or space admins. This creates several issues: - Root admins become a bottleneck for routine login policy changes. - Platform operators need to manually support requests from individual teams. - Teams managing their own spaces cannot fully own their access model. - Dynamically created child spaces are difficult to support because the root admin may not have the right context. - Centralised ownership does not scale well in large or federated organisations. The result is additional operational overhead, slower delivery, and unnecessary dependency on central administrators.

Please authenticate to join the conversation.

Upvoters
Status

πŸ‘€ In Review

Board

πŸ’‘ Feature Requests

Tags

Access Control

Date

About 20 hours ago

Subscribe to post

Get notified by email when there are changes.