Product Feedback: Suggestion to improve the permission to view audit logs for custom roles | Community
Skip to main content
Delivered

Product Feedback: Suggestion to improve the permission to view audit logs for custom roles

Related products:Admin Center
  • February 6, 2026
  • 6 replies
  • 0 views

Following the introduction of the “View audit logs” permission described in the this announcement, we have identified a concern regarding the effective scope of this permission. When the option is enabled for a team member, the interface also displays the “Manage settings” button, which allows users to modify the “Automatically delete PII” feature.


Issue Description
The “View audit logs” permission is expected to provide strictly read‑only access to audit information. However, the presence of the “Manage settings” control extends user capabilities beyond this intended scope, granting access to sensitive administrative actions. This results in an unintended elevation of privileges, as users who should only have visibility into audit data are able to change account‑level settings. Additionally, providing access to the “Automatically delete PII” option under a permission that is meant to be view‑only introduces unnecessary compliance and data‑governance risks. This situation also deviates from established least‑privilege principles, as a permission associated with viewing audit logs should not expose configuration mechanisms that have operational and regulatory implications.


Suggested Improvement
We recommend that Zendesk remove or hide the “Manage settings” button for users who are assigned only the “View audit logs” permission. This control, and the ability to enable “Automatically delete PII”, should be restricted exclusively to users with appropriate administrative rights. Ensuring that “View audit logs” remains strictly read‑only would provide clearer permission boundaries and prevent unintended access to sensitive settings.


Impact and Benefits
Implementing this refinement would strengthen account security, support compliance obligations, and reduce the risk of unauthorized or accidental changes to data‑retention configurations. It would also ensure greater clarity in how permissions are applied, resulting in a permission model that more accurately reflects industry standards and customer expectations.

6 replies

Dan30
  • February 9, 2026
Hi Georgi,
 
Thank you for taking the time to provide us with your feedback. This has been logged for our PM team to review. For others who may be interested in this feature request, please add your support by upvoting this post and/or adding your use case to the comments below. Thank you again!

Alina12
  • February 11, 2026
Thank you for taking the time to provide us with this feedback! 
 
This is a great feature request and I have added it to the backlog for development. We are going to leave this post open for comment to allow others to provide their feedback and use cases, however please note as is stated in our Community Guidelines that we can not commit to prioritizing any one piece of feedback we receive in the community. 
 
Thank you again for your feedback and for being a valuable customer with Zendesk.

Alina12
  • February 24, 2026

I wanted to closed the loop and let you know that we updated this functionality per your request. “Manage settings” button for users who are assigned only the “View audit logs” permission is now removed from the page.


  • Author
  • February 25, 2026

Hi Alina,

I have tested this after enabling the “View audit logs” permission for the custom role assigned to me, and I am still able to see and select the “Manage settings” button.
Please note that I refreshed the page multiple times, logged out and back in several times, and also tested in an incognito window; however, the behavior remains unchanged.
Could you please double‑check this on your end and advise accordingly?


Alina12
  • March 4, 2026
Hi Georgi, I did a triple check on my account and the "Manage settings" is gone. The only button that shows on my account is "Email CSV". If you'd like to email me at alina[dot]wright @ zendesk.com and I can help triage. 

  • Author
  • March 5, 2026

Hi Alina, 

Thanks for confirming.

I have reviewed it and can confirm that the ‘Manage settings’ button is not visible when this permission is enabled.