-
Suggestion
-
Resolution: Unresolved
-
None
-
None
-
3
-
0
-
NOTE: This suggestion is for Confluence Server. Using Confluence Cloud? See the corresponding suggestion.
We manage all of our permissions in Active Directory via permissions groups that follow a strict naming convention to specify space permissions. For example:
- TOOL_Confluence_Main_Admin: This group has Admin permissions in the "Main" space.
- TOOL_Confluence_Main_Edit: This group has edit permissions in the "Main" space
- TOOL_Confluence_Main_Comment: This group has comment permissions in the "Main" space
- TOOL_Confluence_Main_View: This group has view-only permissions in the "Main" space
The idea is that all permissions are managed in Active Directory, and it is very easy to see exactly who has permissions in which Confluence spaces, and what level of permissions they have - both inside AD and inside Confluence.
We have trained all the Confluence System Administrators to set permissions up this way when a new space is created - and only system admins are allowed to create site level spaces. The problem is, there is no reasonable way to restrict the management of permissions to ONLY Confluence System Administrators.
We could make it so that ONLY Confluence System Administrators have "Admin" permissions in all spaces. The problem with this option is that teams and departments then have no way of doing the other space administration tasks that we would like to allow them to do such as customizing their sidebars.
Security is the other important factor here. It is important that only trained administrators manage permissions because untrained users may grant permissions to groups that are too broad and include external contractors that should only have limited access to spaces on an as-needed basis.
My request is as follows:
(1) Add a "Permissions" checkbox on the space permissions page - or modify the exiting "restrictions" checkbox to also apply to permissions.
(2) Make it so that if "Permissions" or "Restrictions" is unchecked then the user cannot manage permissions or restrictions - even if the "Admin" box is checked. Currently, with the Admin box checked, a Space Administrator can manage restrictions, even if the "Restrictions" box is not checked.
- is cloned from
-
CONFSERVER-15172 Partial space admin permission/authority
- Closed
- relates to
-
CONFCLOUD-37088 Separate permissions management from space administration
- Gathering Interest
Form Name |
---|
We need to restrict Space Admin from adding users and groups to spaces for CUI access control. Thank you.