keybase / keybase/keybase-issues

Team role to only manage subteam access for other users

Open
#4,016 0 comments 0 reactions 0 assignees View on GitHub
Dominant language
No language data
Stars
899
Forks
40
PR merge metrics
No merged PRs in 30d

Description

Hi team,

We are currently exploring Keybase as an option to have secrets shared between multiple users and teams.
We find the subteam feature very useful to provide a narrow scope of users to access some set of secrets, however we found a bit of an issue with Owners and Admins.

These roles are able to create subteams and manage subteams members, even being able to add themselves as part of the subteam without any required approval.

This effectively makes any owner or admin user of the root team able to access all existing secrets through all subteams.

To us this is quite an inconvenience and would rather have either:
- Approval from subteam admin / owner to let any new user in
- A specific team role which allows managing subteams without being able to add themselves to those

Is this something that could be achievable?
Thanks!

Contributor guide

No contributing guide indexed for this repository

Research direction

The issue names no files, tests, or entry points. First clarify whether the desired behavior is approval for membership or a role that can manage subteams without joining them; done should preserve delegated management while preventing unauthorized access through self-addition.

Written by the indexing model from the issue text.

Assessment

Domain
authorization
Issue type
Feature
Difficulty
5/5
Estimated time
Over a week
Activity status
Stale
Clarity
Needs clarification
Newbie friendliness
25/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.