Granular user management permissions

The ability to grant permissions to certain organization scoped things like updating users, so API keys can adhere to the principle of least privilege.

Workaround
Using an API key "Space admin" on the root space
Problem
We have a process that sync's users slack IDs into Spacelift for use with the Slack integration, which calls the "managedUserUpdate" GraphQL mutation to update users. Currently we have to give this a key with Space admin on the root space, which is far more permissive than we'd like. More generally, it seems that any organization level settings currently require these privileges, which are likely more permissive than needed in many cases.

Please authenticate to join the conversation.

Upvoters
Status

πŸ‘€ In Review

Board

πŸ’‘ Feature Requests

Tags

Access Control

Date

About 14 hours ago

Subscribe to post

Get notified by email when there are changes.