Allow Admins to impersonate lower level admins



Publicado 10 ago 2021

We currently have about 12 admin roles in our Zendesk instance, and it's sometimes not possible to know what permissions users in those roles will have. An example that came up today was that we weren't sure which roles would allow a user to change the groups for another user. This makes it difficult to answer security questions like 'what permissions does this user have' or 'who has access to this feature/field'.

While it would be great to show all the permissions a role has on the role page, that may not be realistic at this time. One solution that we've seen implemented elsewhere is to allow impersonation of an admin so that someone can see what the lower level admin has access to. This also helps when providing internal support to users as you can see what they see.

Typically this comes with a few provisos - usually the admin you're impersonating can't have more permissions than you have (this could also be limited so that only those with the full 'Administrator' role can impersonate), and if the admin makes any changes to records those changes would be associated with the impersonator not the person being impersonated. 


2

4

4 comentarios

image avatar

Alina Wright

Zendesk Product Manager

Hi Mark - product manager from Zendesk here. I'm currently conducting research around permissions and would love to learn more. Can you walk me through your different levels of permissions for your 12 admin roles? e.g. why 12 admins and not other roles? What are you designating these admins to do? Are you tracking their permissions outside of impersonation?

Feels like a lot of manage and I wonder if there's a better way we can serve your needs.

Thanks so much!

0


image avatar

Dwight Bussman

Zendesk Customer Care

There is a feature available within Zendesk that allows Admins (those with the full "Administrator" role) to impersonate any user with lesser permissions (the account owner can impersonate other Administrators, but not vice-versa). 

This can be accessed by visiting https://subdomain.zendesk.com/users 

0


Dwight Bussman - Is there any sort of audit logging for when an Admin impersonates a user with lesser permissions? 

0


image avatar

Dwight Bussman

Zendesk Customer Care

Jared Wilcox - It looks like there is not currently an audit log event for this action. Our support team should be able to pull logs for whether this took place in your account recently. I will make sure our Audit Logs team is aware of this absence. Thanks for pointing it out!

0


Iniciar sesión para dejar un comentario.

¿No encontró lo que buscaba?

Nueva publicación