mirror of
https://github.com/awatertrevi/infisical.git
synced 2026-10-05 09:26:37 +00:00
doc: added doc for assume privilege feature
This commit is contained in:
@@ -0,0 +1,42 @@
|
|||||||
|
---
|
||||||
|
title: "Assume Privileges"
|
||||||
|
description: "Learn how to assume privileges of a user or machine identities in a project."
|
||||||
|
---
|
||||||
|
|
||||||
|
## Overview
|
||||||
|
|
||||||
|
The Assume Privileges feature allows authorized users to temporarily gain the permissions of another user or identity within the system.
|
||||||
|
This capability enables administrators to troubleshoot issues, perform maintenance tasks, or assist users without requiring permanent access to their accounts.
|
||||||
|
|
||||||
|
## How It Works
|
||||||
|
|
||||||
|
When an authorized user activates the Assume Privileges feature, they temporarily inherit the exact permissions of the target user or identity for a limited time period (1 hour).
|
||||||
|
During this period, they can perform actions within the system as if they had the same permission level as the target user.
|
||||||
|
|
||||||
|
- **Permission-based**: Only transfers permissions, not the complete identity
|
||||||
|
- **Time-limited**: Access automatically expires after 1 hour
|
||||||
|
- **Audited**: All actions performed during the privilege assumption are logged under the original user's credentials
|
||||||
|
- **Authorization-required**: Only users with specific **assume privilege** permission can use this feature
|
||||||
|
|
||||||
|
### Distinction from Impersonation
|
||||||
|
|
||||||
|
Unlike impersonation, Assume Privileges:
|
||||||
|
|
||||||
|
1. Does not change the user's display name or identity in the system
|
||||||
|
2. Records all actions under the original user's ID (not the target user)
|
||||||
|
3. Only provides access to permissions, not personal settings or data
|
||||||
|
4. Is designed for administrative and support purposes within proper authorization boundaries
|
||||||
|
|
||||||
|
## Steps
|
||||||
|
|
||||||
|
1. Navigate to Project Access and select a user/identity by clicking on their row in the table
|
||||||
|

|
||||||
|
2. Click the Assume Privilege button and type in assume to confirm and start your session
|
||||||
|

|
||||||
|
3. A yellow alert session will appear showing your active assume privilege session; you can exit at any time by clicking the \*\*Exit button
|
||||||
|

|
||||||
|
|
||||||
|
<Info>
|
||||||
|
The assume privilege session is scoped to a single project and will expire
|
||||||
|
after 1 hour. A user can only assume privileges for one project at a time.
|
||||||
|
</Info>
|
||||||
Binary file not shown.
|
After Width: | Height: | Size: 335 KiB |
Binary file not shown.
|
After Width: | Height: | Size: 360 KiB |
Binary file not shown.
|
After Width: | Height: | Size: 439 KiB |
+3
-2
@@ -160,6 +160,7 @@
|
|||||||
},
|
},
|
||||||
"documentation/platform/access-controls/additional-privileges",
|
"documentation/platform/access-controls/additional-privileges",
|
||||||
"documentation/platform/access-controls/temporary-access",
|
"documentation/platform/access-controls/temporary-access",
|
||||||
|
"documentation/platform/access-controls/assume-privilege",
|
||||||
"documentation/platform/access-controls/access-requests",
|
"documentation/platform/access-controls/access-requests",
|
||||||
"documentation/platform/access-controls/project-access-requests",
|
"documentation/platform/access-controls/project-access-requests",
|
||||||
"documentation/platform/pr-workflows",
|
"documentation/platform/pr-workflows",
|
||||||
@@ -887,8 +888,8 @@
|
|||||||
]
|
]
|
||||||
},
|
},
|
||||||
{
|
{
|
||||||
"group": "LDAP Password",
|
"group": "LDAP Password",
|
||||||
"pages": [
|
"pages": [
|
||||||
"api-reference/endpoints/secret-rotations/ldap-password/create",
|
"api-reference/endpoints/secret-rotations/ldap-password/create",
|
||||||
"api-reference/endpoints/secret-rotations/ldap-password/delete",
|
"api-reference/endpoints/secret-rotations/ldap-password/delete",
|
||||||
"api-reference/endpoints/secret-rotations/ldap-password/get-by-id",
|
"api-reference/endpoints/secret-rotations/ldap-password/get-by-id",
|
||||||
|
|||||||
Reference in New Issue
Block a user