Permission Delegation allows administrators to grant scoped administrative access to specific management areas in Staffbase Studio without assigning full administrator access.
Most non-content management activities in Studio require the administrator role, which provides full access to settings, user accounts, and security controls. However, organizations often need to delegate specific tasks, such as managing users or importing data, without giving users access to the rest of Studio. With Permission Delegation, administrators can grant users, groups, or API tokens access to specific management areas based on the tasks they need to perform.
How Permission Delegation Works
Administrators assign permissions through a dedicated area in Studio. Permissions can be assigned to individual users, groups, or API tokens.
An assigned account or tokens can access only the management areas to which it has been explicitly granted access. It cannot access other Studio management areas unless it has the required permissions through another role or assignment.
Permissions are additive. If a user receives access to the same management area through multiple groups or assignments, they retain access as long as at least one assignment remains active. Removing the last assignment immediately revokes access.
Assigned accounts or tokens cannot delegate or pass their delegated permissions on to other accounts or tokens.
Permission Delegation supports the following management areas:
Benefits of Permission Delegation
Scalable Administration
Delegate specific administrative tasks to the people who need them without granting full administrator access. This allows organizations to distribute responsibilities across teams while keeping access limited to the required management areas.
Centralized Control
Administrators retain control over all permission delegation. Delegated users and API tokens cannot grant or pass on their permissions, and removing an assignment immediately revokes access to the associated management area.
Reduced Security Exposure
Scoped permissions limit access to only the management areas required for a task. This reduces the potential impact of unauthorized changes or a compromised account compared with granting full administrator access.
Comments
0 comments
Please sign in to leave a comment.