Skip to main content
Open

Better auditing of which users, roles and permissions have access to Control

Related products:CC Users & Roles
jaclyn_st_gemme
wayne_baker
  • jaclyn_st_gemme
    jaclyn_st_gemme
  • wayne_baker
    wayne_baker

Blastoise186

Hiya!

This one’s inspired by a recently discovered (and thankfully fixed!) bug that I came across in the last month or so. I can’t reveal the exact details of that bug though for a few complicated reasons. This is technically a security related idea, but I judge the risk to be low enough to post the idea since it’s private anyway and the related bug has already been fixed. Thanks @tom.shaddock by the way! :)

I also want to give some Co-Author credit to @timcavey as he was involved with this stuff.

But one thing that would really help a lot, would be better auditing and insights into exactly who has access to Control, especially on the basis of:

  • Individual Users
  • Roles
  • Permissions
  • Ranks
  • Anything else that can grant Control access

In particular, having a way to quickly see this information at a glance with the ability to modify or revoke such permissions in one place would be great. A bit like how Google Workspace has a dedicated section under both Users and Admin Roles that can spit out a report of exactly who has administrator rights and therefore access to Google Admin.

As a slight bonus, perhaps also make it so that if a particular user does not access Control for a certain amount of time (such as six months), flag it up to the Administrator and/or Community Manager with a recommendation to consider whether that user still needs Control access and provide a way to revoke it if they no longer need it (along with details on exactly how/why they currently have Control permissions). You could potentially also do it in a way that works with Roles/Ranks as well - so that an entire Role and/or Rank gets flagged up if no-one who has that Role/Rank doesn’t use Control at all for X time and doesn’t have a Primary Role that already grants access, so that Moderators don’t interfere with the alerts and to help prevent false positives/false negatives on the role/rank based alerting.

This isn’t intended to automatically nuke permissions just because they’re not used - because there can be use cases where you go long periods without touching anything. But it is intended to at least let someone know about it so that a manual review can take place if needed.

3 replies

timcavey
Forum|alt.badge.img
  • Helper ⭐️⭐️
  • 269 replies
  • July 8, 2021

I must say that I was pleasantly surprised to hear that custom user roles can have some permissions easily added (and removed) on Control. I was always thinking this was limited to admin roles. The next stage would be to allow ‘some’ of these extra permissions directly via the front end, keeping Control for the admins. 

 

I know there’s an open idea for this somewhere…..


alex.timmermann
  • Gainsight Employee ⭐️
  • 37 replies
  • September 1, 2021

Hi folks! Sorry for the late reply on this. I can see how something like that would be useful! We currently don’t have anything planned in this direction, but I’ll leave the idea open to gather some more votes 🙂


alex.timmermann
  • Gainsight Employee ⭐️
  • 37 replies
  • September 1, 2021
Updated idea statusNewOpen


Cookie policy

We use cookies to enhance and personalize your experience. If you accept you agree to our full cookie policy. Learn more about our cookies.

 
Cookie settings