
Anyone working in Zscaler operations needs permissions. Because graded rights take effort and full rights work immediately, many organisations end up with far more administrator accounts than they need. Graded roles solve more than a security question: they make it possible in the first place to hand tasks to the service desk or to junior colleagues without weighing the risk anew at every handover.
Why full rights are so tempting
A new colleague is to work in Zscaler operations. She needs access, otherwise she cannot start. The question of which rights exactly takes time to answer and has to be asked again for every special case.
Full rights solve that immediately and completely. They always work, for every task, without adjustment. That convenience is the real reason administrator accounts multiply, not carelessness.
The price falls due later, and elsewhere: in an audit conversation, in an incident analysis, or the moment someone accidentally changes something they never meant to touch.
The real benefit is not security
Graded roles are usually treated as a security topic. That falls short. Their greater benefit is that they make delegation possible at all.
As long as any involvement requires full rights, every handover of a task is a risk decision. Can the service desk take on this diagnosis? Only if they become administrators, so better not. The task stays with second level, even though it does not belong there.
With graded rights, the risk question becomes a scoping question: which view does this role need to do this job? That can be answered, and the task can then go where it is handled efficiently.
Reading is the most common requirement
A large part of daily work consists of looking things up. Where is it stuck, which rule applies, what is the state of this device. None of that requires write access.
That observation is the most practical shortcut to a sensible role design. Separating the reading activities from the writing ones solves most of the problem, without having to design a fine-grained rights model.
What happens to the write permissions
For changes, the question of who may carry them out remains. A second layer helps here: not every change has to take effect immediately. Critical interventions can be tied to a four-eyes approval.
This decouples the right to prepare a change from the right to release it. A junior colleague can work without every change going live at once, and learns on real cases while doing so.
What the account list says about the organisation
A good first step is a plain question: how many accounts hold full rights, and how many people actually need them daily? The gap between the two numbers is usually larger than expected.
That gap is no reproach to anyone involved. It is the predictable result of full rights being the path of least resistance. Closing it is therefore less a matter of discipline than of tooling.
Count the accounts with full administrator rights, and next to them the people who need them daily. The difference is the size of the task.
Frequently asked questions
Why are many super admin accounts a problem?
Because each one means full access to everything, including areas the person never touches. An accidental change or a compromised account then has unlimited effect.
What is the most practical first step?
Separating reading activities from writing ones. A large part of daily work consists of looking things up and needs no write access.
What do permissions have to do with delegation?
As long as involvement requires full rights, every handover is a risk decision. Graded rights turn that risk question into a scoping question and make delegation possible.
How do I handle change permissions?
Through a second layer: critical changes can be tied to a four-eyes approval. That separates the right to prepare a change from the right to release it.
Do I have to design a fine-grained rights model?
No. Most of the benefit comes from separating reading and writing activities. Finer distinctions can follow later.
Sources
See the workflow in context
Pick the matching role in the demo launcher. The demo uses prepared sample data.
Open demo launcher