What's next from Grafana Labsbreadcrumb arrow Role managers can remove permissions they don't hold
What's next from Grafana Labs
What's next from Grafana Labs
Behavior change
Enterprise Authentication and authorization
Announcement
2026-09-17
Planned rollout in Cloud
2026-09-28
Targeted self-managed release
grafana-v13.3.0

Role managers can remove permissions they don't hold

The legacy role-based access control (RBAC) HTTP API will let authorized role managers revoke access without holding the permissions being removed. This applies when you remove permissions from a role, delete an editable custom role, or remove role assignments from users or teams. Each operation will still require its management permissions.

If you delegate role management or use integrations with /api/access-control/ endpoints, review who should have this broader revocation authority. Otherwise, you don’t need to take action.

Role updates and deletion

Previously, you had to hold a permission to remove it from a role. After this change, when you update a role, Grafana will check every permission in the submitted permissions array, including permissions you keep. It won’t check permissions you remove.

You’ll also be able to delete an editable custom role without holding the permissions it grants.

An explicit empty permissions array clears the role’s permissions. Omitting permissions leaves them unchanged.

For example, consider a role with folders:read and users:read, both with scope *. You hold folders:read with that scope, but not users:read.

The following requests to PUT /api/access-control/roles/{roleUID} illustrate the difference.

Allowed after this change
JSON
{
  "permissions": [
    { "action": "folders:read", "scope": "*" }
  ]
}

Grafana will accept this request for an editable role because you hold the retained folders:read permission. You won’t need to hold the removed users:read permission.

Still rejected
JSON
{
  "permissions": [
    { "action": "folders:read", "scope": "*" },
    { "action": "users:read", "scope": "*" }
  ]
}

Grafana will reject this request because it keeps users:read, a permission you don’t hold.

Role assignment changes

Previously, removing a role assignment required you to hold the permissions granted by that role. After this change, you’ll be able to remove a role from a user or team without holding those permissions. This also applies when you remove roles while replacing a user’s or team’s assignments. Assigning a new role will still require you to hold its permissions.

When replacing all assignments for a role, you’ll be able to clear every assignment without holding that role’s permissions. If the submitted replacement keeps any assignments, you’ll still need to hold those permissions.

Grafana Admin role updates

Updates to the built-in Grafana Admin role, identified by basic_grafana_admin, will require Grafana server administrator status. Organization Admin status alone will no longer be sufficient, including for metadata-only updates.

Why we’re changing it

You might need to remove excessive or obsolete access even when you don’t hold that access yourself. Requiring you to have those permissions before you revoke them can block access cleanup, whether you’re reducing a role’s permissions, deleting a custom role, or removing a role assignment.

What isn’t changing

The API endpoints, request fields, and response formats remain unchanged. You still need the management permission required by each operation, including the permissions:type:delegate scope.

Grafana still validates every permission you submit. Creating or assigning roles still requires you to hold the permissions you delegate.

Built-in roles remain protected from deletion. The Admin, Editor, and Viewer basic roles remain editable under the submitted-permission rule.

File provisioning and the explicit role hard-reset operation are unchanged. No compatibility flag preserves the previous removal checks.

What to check before this rolls out

  • Delegated managers: Review who has roles:write, roles:delete, users.roles:remove, or teams.roles:remove with the permissions:type:delegate scope. Remove grants from anyone who shouldn’t be able to revoke access they don’t hold before September 28, 2026.
  • Role-update integrations: If you have an integration that updates roles, verify that every submitted permissions array contains the complete intended resulting permission set. An explicit empty array clears all permissions.
  • Grafana Admin role: If you have an integration that updates basic_grafana_admin, run it with Grafana server administrator credentials before September 28, 2026. Requests that use Organization Admin credentials will receive 403 Forbidden.
  • Tests: Update tests that expect removal requests to fail solely because you lack a removed permission. Keep tests for missing management permissions and for retained or newly added permissions you can’t delegate.

Related What's next posts