払い出されたインスタンスのAdminユーザーで「グループ」および「ユーザー」に「admin」ロールを付与することができない

Takuma Sato
Tera Contributor

今回参加するHackathonJapanの私たちのチームは複数メンバーが開発を行います。
そのため、払い出されたインスタンスに対してメンバーそれぞれのユーザーを作成し「admin」と「security_admin」の付与を行おうとしております。
払い出されたインスタンスのAdminユーザー(System Administrator)で開発メンバーそれぞれのユーザー作成を行おうとしておりますが、
adminロールをユーザーやグループの関連リストから付与しようとしても空打ちになってしまいます。
そのため「sys_group_has_role」にてグループとロールを指定のうえ保存したところ
Unable to execute UI Action because user does not have permission to create the current record」のエラーメッセージが表示されました。
今回、ロール昇格していても同じ事象となるため「admin」ロールの付与の方法を教えていただきたく存じます。
※「security_admin」ロールは正常に付与できますが、「admin」ロールのみ付与できないことを確認しております。

1 件の受理された解決策

Rafael Batistot
Kilo Patron

Hi @Takuma Sato 

 

The admin role is a “base system role” that cannot be assigned manually (neither through the UI related list nor by inserting records into sys_user_has_role or sys_group_has_role). Only the initial “System Administrator” account that comes with the instance has this role.

 

That’s why:

  • You can grant security_admin, because it is designed to be elevated and delegated.
  • You cannot grant admin to other users, even as a full admin, because the platform blocks it for security reasons.

 

it’s not a bug, but a platform restriction. The only way to have multiple admin users in your hackathon instance is if the event organizers grant them.

If you found this response helpful, please mark it as Helpful. If it fully answered your question, consider marking it as Correct. Doing so helps other users find accurate and useful information more easily.

元の投稿で解決策を見る

2件の返信2

Rafael Batistot
Kilo Patron

Hi @Takuma Sato 

 

The admin role is a “base system role” that cannot be assigned manually (neither through the UI related list nor by inserting records into sys_user_has_role or sys_group_has_role). Only the initial “System Administrator” account that comes with the instance has this role.

 

That’s why:

  • You can grant security_admin, because it is designed to be elevated and delegated.
  • You cannot grant admin to other users, even as a full admin, because the platform blocks it for security reasons.

 

it’s not a bug, but a platform restriction. The only way to have multiple admin users in your hackathon instance is if the event organizers grant them.

If you found this response helpful, please mark it as Helpful. If it fully answered your question, consider marking it as Correct. Doing so helps other users find accurate and useful information more easily.

HI @Rafael Batistot 

Thank you for taking the time to explain everything so clearly.
I was planning to set things up the way I usually do for development, but I understand that the HackathonJapan instance has certain security restrictions.
If that’s acceptable, I’ll proceed using the “System Administrator” account.