Too many techs with full permissions! Is that a problem?Solved

Participant
Discussion
6 days ago Feb 24, 2026

Quick question. 

How many of you actually limit full-access roles in Hexnode? 

Right now, we’ve got around 4–5 technicians with a custom role that basically has every permission enabled because “it’s easier.” 

Starting to think that might not be a great idea. 

Replies (8)

Marked SolutionPending Review
Participant
6 days ago Feb 24, 2026
Marked SolutionPending Review

Yeah… that’s usually how it starts 😅. 

We did the same in the beginning. Instead of defining proper roles, we just enabled all permissions for most of the team. 

Works fine… until it doesn’t. 

Marked SolutionPending Review
Participant
6 days ago Feb 24, 2026
Marked SolutionPending Review

What made you change it, @noor_k ? 

Marked SolutionPending Review
Participant
5 days ago Feb 25, 2026
Marked SolutionPending Review

Two things. 

First, someone edited a live policy thinking it was a test one. It pushed changes to way more devices than intended. 

Second, we stepped back and realized that “full access” means everything — policy creation, deletion, device wipe, app removal, technician management… the whole portal. 

Most people didn’t actually need that level of control. So, we broke it down into proper custom roles instead. 

Marked SolutionPending Review
Participant
5 days ago Feb 25, 2026
Marked SolutionPending Review

Same here. We now have separate roles: 

  • Helpdesk → device-level actions only 

  • Policy admin → policy management 

  • App admin → app repository + deployments 

 Only a couple of people have a role with broad permissions. 

Marked SolutionPending Review
Participant
4 days ago Feb 26, 2026
Marked SolutionPending Review

Did that create delays? Do you have to ask someone else every time? 

Marked SolutionPending Review
Participant
4 days ago Feb 26, 2026
Marked SolutionPending Review

Not really. 

Once roles are defined properly, people don’t feel restricted. They just don’t have unnecessary access anymore. 

And if someone genuinely needs extra permissions for a task, we update the role temporarily. 

Marked SolutionPending Review
Participant
4 days ago Feb 26, 2026
Marked SolutionPending Review

The biggest benefit for us was risk reduction. 

If a technician account gets compromised and it has full access, that’s serious damage. If it’s limited to just device-level actions, the impact is much smaller. 

Marked SolutionPending Review
Participant
3 days ago Feb 27, 2026
Marked SolutionPending Review

Makes sense. I think we gave broad access out of convenience, not necessity. 

Time to clean that up. 

Save