Role managers can remove permissions they don't hold
The legacy role-based access control (RBAC) HTTP API will let authorized role managers revoke access without holding the permissions being removed. This applies when you remove permissions from a role, delete an editable custom role, or remove role assignments from users or teams. Each operation will still require its management permissions.
If you delegate role management or use integrations with /api/access-control/ endpoints, review who should have this broader revocation authority. Otherwise, you don’t need to take action.
Role updates and deletion
Previously, you had to hold a permission to remove it from a role. After this change, when you update a role, Grafana will check every permission in the submitted permissions array, including permissions you keep. It won’t check permissions you remove.
You’ll also be able to delete an editable custom role without holding the permissions it grants.
An explicit empty permissions array clears the role’s permissions. Omitting permissions leaves them unchanged.
For example, consider a role with folders:read and users:read, both with scope *. You hold folders:read with that scope, but not users:read.
The following requests to PUT /api/access-control/roles/{roleUID} illustrate the difference.
Allowed after this change
{
"permissions": [
{ "action": "folders:read", "scope": "*" }
]
}Grafana will accept this request for an editable role because you hold the retained folders:read permission. You won’t need to hold the removed users:read permission.
Still rejected
{
"permissions": [
{ "action": "folders:read", "scope": "*" },
{ "action": "users:read", "scope": "*" }
]
}Grafana will reject this request because it keeps users:read, a permission you don’t hold.
Role assignment changes
Previously, removing a role assignment required you to hold the permissions granted by that role. After this change, you’ll be able to remove a role from a user or team without holding those permissions. This also applies when you remove roles while replacing a user’s or team’s assignments. Assigning a new role will still require you to hold its permissions.
When replacing all assignments for a role, you’ll be able to clear every assignment without holding that role’s permissions. If the submitted replacement keeps any assignments, you’ll still need to hold those permissions.
Grafana Admin role updates
Updates to the built-in Grafana Admin role, identified by basic_grafana_admin, will require Grafana server administrator status. Organization Admin status alone will no longer be sufficient, including for metadata-only updates.
Why we’re changing it
You might need to remove excessive or obsolete access even when you don’t hold that access yourself. Requiring you to have those permissions before you revoke them can block access cleanup, whether you’re reducing a role’s permissions, deleting a custom role, or removing a role assignment.
What isn’t changing
The API endpoints, request fields, and response formats remain unchanged. You still need the management permission required by each operation, including the permissions:type:delegate scope.
Grafana still validates every permission you submit. Creating or assigning roles still requires you to hold the permissions you delegate.
Built-in roles remain protected from deletion. The Admin, Editor, and Viewer basic roles remain editable under the submitted-permission rule.
File provisioning and the explicit role hard-reset operation are unchanged. No compatibility flag preserves the previous removal checks.
What to check before this rolls out
- Delegated managers: Review who has
roles:write,roles:delete,users.roles:remove, orteams.roles:removewith thepermissions:type:delegatescope. Remove grants from anyone who shouldn’t be able to revoke access they don’t hold before September 28, 2026. - Role-update integrations: If you have an integration that updates roles, verify that every submitted
permissionsarray contains the complete intended resulting permission set. An explicit empty array clears all permissions. - Grafana Admin role: If you have an integration that updates
basic_grafana_admin, run it with Grafana server administrator credentials before September 28, 2026. Requests that use Organization Admin credentials will receive403 Forbidden. - Tests: Update tests that expect removal requests to fail solely because you lack a removed permission. Keep tests for missing management permissions and for retained or newly added permissions you can’t delegate.