Project

General

Profile

Actions

Feature #3193

closed

Allow compartmentalisation/filtering of permissions by Organistion/Location

Added by Ken Coar about 11 years ago. Updated over 8 years ago.

Status:
Resolved
Priority:
Normal
Assignee:
-
Category:
Users, Roles and Permissions
Target version:
-
Difficulty:
Triaged:
Fixed in Releases:
Found in Releases:

Description

It would be nice if a user in an organisation could be granted 'edit user' access (etc.) solely for other users within his organisation. (Ditto for location.)

As with the usual separation of powers model, the permission should not allow the privileged user to elevate any others to his own level. (E.g., in IRC, you typically can only grant your-access-minus-one to others.)

With a limited number of administrators, the ability to delegate this sort of self-maintenance to organisations would be extremely useful.

Perhaps this can be done as simply as adding the organization and location bits to the filter list on the user profile page.


Related issues 3 (1 open2 closed)

Related to Foreman - Feature #812: cant assign roles to groups, just to usersClosedMarek Hulán03/31/2011Actions
Blocks Foreman - Tracker #4552: New permissions/authorization system issuesNew

Actions
Blocked by Foreman - Bug #5929: Taxonomy selectors do not obey assign_$taxonomy permissionsClosedMarek Hulán05/26/2014Actions
Actions

Also available in: Atom PDF