The user should be updatable, their authorized key should be able to change, their password, and if they are sudoers no not