cockroach-staging / hello-world

0 stars 0 forks source link

S505: (out of scope for 2019) As an "owner" of the managed service account for my organization, I want to make sure no other admin can remove me, so that I can guard against rogue admin employees who might remove me or accidental removals of my admin r... #573

Open exalate-issue-sync[bot] opened 4 years ago

exalate-issue-sync[bot] commented 4 years ago

(out of scope for 2019) As an "owner" of the managed service account for my organization, I want to make sure no other admin can remove me, so that I can guard against rogue admin employees who might remove me or accidental removals of my admin role.

exalate-issue-sync[bot] commented 4 years ago

Rachel Casali commented: From Marc

I've historically found a "special" user to be incredibly annoying. When you want to pass the torch to someone else, you either need to "reassign" the main user, or file a ticket.

There's also the risk of having things that can only be done by that main user. If they're away, there's no alternative but to wait.

I instead propose that all MSO admins have the same permissions, including removing other admins with no exceptions.