What's new from Grafana Labsbreadcrumb arrow Role managers can revoke access they do not hold
What's new from Grafana Labs
What's new from Grafana Labs
Grafana Cloud Generally Available Enterprise Generally Available Authentication and authorization Breaking change
Release date
2026-10-02
Self-managed release
grafana-v13.3.0

Role managers can revoke access they do not hold

If you have the required permissions to manage roles or role assignments, you can revoke access without holding the permissions being removed. This applies when you update or delete a role, or remove role assignments through the /api/access-control/ APIs.

If you delegate role management, review who should have this broader revocation authority, as outlined in the advance notice.

Role updates and deletion

When you update a role, Grafana checks the permissions you submit, including those you keep. You don’t need to hold the permissions you remove. You can also delete a custom role without holding the permissions it grants.

For example, you have roles:write with scope permissions:type:delegate. You want to update a role that grants folders:read and users:read, both with scope *. You hold folders:read with that scope, but not users:read.

The submitted permissions array replaces the role’s current permissions. These requests to PUT /api/access-control/roles/{roleUID} illustrate the difference.

Removing a permission

This request removes users:read and keeps folders:read:

JSON
{
  "permissions": [
    { "action": "folders:read", "scope": "*" }
  ]
}

Grafana accepts this request because you hold the retained permission. You don’t need the removed users:read permission.

Retaining a permission you don’t hold

This request keeps both permissions:

JSON
{
  "permissions": [
    { "action": "folders:read", "scope": "*" },
    { "action": "users:read", "scope": "*" }
  ]
}

Grafana rejects this request because it retains users:read, a permission you don’t hold.

An explicit empty permissions array clears the role’s permissions. Omitting permissions leaves them unchanged.

Role assignments

You can remove a role from a user or team without holding the permissions that role grants. This also applies to roles you remove when replacing a user’s or team’s assignments. Assigning a new role still requires you to hold its permissions.

When replacing all assignments for a role, you can clear every assignment without holding that role’s permissions. If the submitted replacement includes any assignments, you still need to hold those permissions.

Grafana Admin role updates

Updating the built-in Grafana Admin role (basic_grafana_admin) requires Grafana server administrator status, including for metadata-only updates. If your integration uses Organization Admin credentials, switch to Grafana server administrator credentials; Organization Admin status alone results in 403 Forbidden.

Availability

The change is rolling out to Grafana Cloud and is available on the instant and fast release channels. The steady channel is currently scheduled for October 6, 2026, and the slow channel for October 26, 2026.

Grafana Enterprise will include this change in the upcoming Grafana 13.3 release.


Related What's new posts