Yiannis,
I agree with
@Seth Loomer
I think what is not being understood is that when hosting and managing systems for clients, we have a hierarchy of management staff and levels of trust. I understand some of the important security enhancements made, but this also opens up others and creates problems.
We operate and need something more like this:
Root admin. Access/change anything. Would be nice if root could assign sub root admins that cannot change passwords for other admins but have most rights so root does not have to be shared.
Root managers have most rights like Gen sys admin, but not things like sip trunk management.
General managers (mostly at the remote client locations) with General Sys Admin (taken away recently) Manage All Extensions that need to change extensions, names, send welcome emails, reports, recordings; basic operating stuff.
Supervisors, like Seth said, have been delegated the extra right to run reports/recordings, maybe log a user out of queue or change their status from the console that might have forgotten.
Basic extension users with no console rights.
With the new changes, these supervisors extensions cannot be seen or any type of edit made, status changed unless using root admin, which we don't want to share with root managers, general managers.
All of the levels with manage all extensions should be able to see all extensions in the system, send welcome emails, change status, but not necessarily be able to access/change passwords for levels equal or above them and maybe some other stuff I'm not thinking of right now..
We'll have serious backlash from the managers at the client locations when extensions aren't visible or manageable because they have a right such as call reports and recordings.
We've already taken a beating for removing General System Admin to remove some nodes for security like Backup/Restore, as now the managers cannot add and remove their agents from queues themselves without calling.
It's complicated to revamp the security, I know. But we are trying to maintain the security and integrity of hosting the system, while still allowing the client to access the features they need to run and maintain their business and can be trusted to manage.
I guess at this point to go to v16, we'll need to follow the advice in another post to set up a dummy extension for accessing call reports/recordings and take those rights off the real extension.