Plan requirement
| Subscription | Any plan |
| Access | Admin |
No, and that is deliberate. Somebody else has to do it, which is the point: every role change then has one person who asked and one who agreed.
Why not
Being able to grant yourself permissions removes the meaning of having them granted. Every access control would be advisory, and an account taken over by somebody would be a full compromise immediately.
The restriction is small and it is doing real work.
What to do instead
Ask another admin. In a healthy account there are two or three, precisely so this is never a blocker.
If you are the only admin
That is the actual problem. One admin means no cover for holidays, no second pair of eyes, and this exact situation when something needs changing.
Make a second one now, before you need them.
If you are the account owner
The owner has options an ordinary admin does not, but the same principle applies to role changes. Another admin handles it.
Reducing your own role
Also not available, for the same reason: it would let somebody quietly remove evidence of what they could do. Ask a colleague.
The useful consequence
Every role change has two people involved: one who asked and one who agreed. That is the audit trail an access review relies on, and it exists because of this restriction.
Comments
0 comments
Article is closed for comments.