Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Is distributed administration possible ? #2673

Closed
adfc-bw opened this issue Apr 5, 2022 · 2 comments
Closed

Is distributed administration possible ? #2673

adfc-bw opened this issue Apr 5, 2022 · 2 comments
Labels
question Further information is requested

Comments

@adfc-bw
Copy link

adfc-bw commented Apr 5, 2022

Describe your question/
currently we are searching for an sso solution. besides the functions and features statet on your website we want to know if we can build a scenario where different (sub)admins can administrate users of specified groups

Relevant infos
We are an NGO with about 250000 members about 20000 of them are active members and contribute to our goals.

The members are widely spread across the country and organised in local groups. The groups themself are hierarchical structured.

Our requirement is, that we have a solution where local (sub)admins can administer the members of the local group and assign permissions (group memberships) to the groups belonging to the local oranisation and thier apps as well as the next level admin can assign permissions to users needing more permissions/apps on the next level of applications.

Is this possible with authentik and if yes how can we achive this ?

@adfc-bw adfc-bw added the question Further information is requested label Apr 5, 2022
@BeryJu
Copy link
Member

BeryJu commented Apr 11, 2022

Hi, this is currently a bit hard to answer. authentik uses an object-based permission system internally so naturally the answer would be yes; however this is currently exposed as an API and cannot be configured. Currently, you can simply configure groups to be admin or not; but things like outpost service accounts already use this permission system.

I am currently working on adding a role system, where a role can have permissions assigned to it, roles are assigned to groups and all permissions in all groups a user is member in will be added. I don't like putting timelines on things but this should be included in the near future.

@BeryJu
Copy link
Member

BeryJu commented Mar 28, 2024

closed by #6806

@BeryJu BeryJu closed this as completed Mar 28, 2024
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
question Further information is requested
Projects
None yet
Development

No branches or pull requests

2 participants