Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Consultant accounts ― who can watch normal non-admin accounts #203

Closed
nhoening opened this issue Oct 4, 2021 · 0 comments · Fixed by #877
Closed

Consultant accounts ― who can watch normal non-admin accounts #203

nhoening opened this issue Oct 4, 2021 · 0 comments · Fixed by #877

Comments

@nhoening
Copy link
Contributor

nhoening commented Oct 4, 2021

We want to allow certain users to see what normal accounts can see.

Use case: Our customer is the supplier to a bunch of other (client) accounts on the server. They should have read-only access to some accounts. At least this is the first step. So they can oversee what happens, for instance for servicing questions and problems.

One easy way for this to happen is giving the account an account-role <client>-watcher or similar. If this role is present, our central auth policy (see e.g. #200) should wave them through if the permission is "read".

This is not thought-through sufficiently yet.

For instance, what if some of the super-account's users deal with one group of client accounts, some with others?

@nhoening nhoening added this to To do in Super accounts via automation Apr 14, 2022
@GustaafL GustaafL linked a pull request Oct 20, 2023 that will close this issue
2 tasks
Super accounts automation moved this from To do to Done Nov 3, 2023
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Projects
Development

Successfully merging a pull request may close this issue.

1 participant