Separation of Administrative and Content Access Roles

Separation of Administrative and Content Access Roles

3 votes

avatar

Hello,
I would like to submit a feature request regarding role management in Devolutions Hub. It would be highly beneficial to allow a clear separation between administrative privileges and access to sensitive content, such as passwords.

More specifically, it would be ideal if an administrator could manage the structure (e.g., create, modify, or delete Vault and folders, manage users and permissions) without automatically having access to the content stored within those folders (e.g., passwords).

For example, the Human Resources team might store shared credentials used internally by their department to access confidential tools or portals. In such cases, it is crucial that only authorized HR team members can view this information, even if a system administrator is responsible for managing the vault’s structure.
While an administrator could technically grant themselves access, such actions should be logged and visible to affected users to ensure full transparency.

This separation of responsibilities would enhance both security and user trust in the platform, while aligning with the principles of least privilege and auditability.

Thank you for considering this suggestion.

All Comments (1)

avatar

Hello,

Thank you for your request. I understand your needs, and they make total sense. We would like to split the administrator role in the future, but it is a challenging job that will have a lot of impacts. We have started to analyze it and hope to be able to work on that in the mid to long term. We will post back here once we have an update.

Best regards,

François Dubois