What Medal Administration Permission Does
Medal administration permission is a setting that lets a user or service account perform administrative tasks within the Medal system — typically creating, modifying, or deleting Medal objects and configurations. When you grant this permission, you're giving someone the ability to manage Medal's core functions rather than just view or use them.
The exact scope depends on your Medal implementation and version. In most setups, an admin can create new Medal instances, adjust settings, manage user access, and handle system-level configurations. A non-admin user might only be able to view existing Medals or perform limited actions within them.
You'll need to grant this permission through your Medal system's user management interface, which is usually accessed by someone who already holds admin rights. The process varies slightly depending on whether you're working with Medal directly, through a cloud platform, or as part of a larger application stack.
Key Takeaways
- Medal administration permission is granted through your system's user management or access control panel, not through code flags or environment variables.
- Only existing administrators can grant this permission to others, so you must contact your system owner or current admin if you need it yourself.
- The permission persists until explicitly revoked, so review who holds admin access regularly to prevent unauthorized changes.
- Most systems log admin actions, so granting this permission creates an audit trail of who made changes and when.
Finding Your User Management Interface
The location of user management depends on your Medal setup. If you're running Medal as a standalone service, look for a settings or administration panel — this is usually accessible from the main dashboard or through a dedicated admin URL that your system owner can provide.
If Medal is running within a larger platform (such as a cloud provider's console, a Docker container management system, or an application framework), the user management may be in that platform's settings rather than Medal's own interface. Check your platform's documentation or ask your team lead where user roles are managed.
Once you locate the interface, you'll typically see a list of users or service accounts. Look for a column labeled "Role," "Permissions," "Access Level," or "Admin Status." This is where you'll make changes.
Granting Permission to a User Account
Open the user management interface and find the user or service account that needs admin permission. Click on that user's entry to open their details or settings page.
Look for a field or checkbox labeled "Administrator," "Admin," "Medal Admin," or "System Administrator." The exact wording varies by implementation. Some systems use a dropdown menu where you select a role (such as "Admin" or "Administrator") from a list; others use a simple toggle or checkbox.
Select or enable the admin option. Most systems will ask you to confirm the change — this is a safety measure to prevent accidental permission grants. Confirm when prompted. The change usually takes effect immediately, though some systems require you to save the entire user record first by clicking a "Save" or "Update" button at the bottom of the page.
Granting Permission to a Service Account
Service accounts (also called bot accounts or system accounts) are non-human identities that applications or automated tasks use to interact with Medal. Granting admin permission to a service account follows the same steps as granting it to a user, but you'll be looking for the service account in the user list rather than a person's name.
Service accounts are often labeled with a prefix like "svc-," "bot-," or "system-" to distinguish them from regular users. If you're unsure whether an account is a service account, check its creation date and last login time — service accounts often show "never" for last login or a date that matches an automated deployment.
After granting permission, verify that the service account can perform its intended tasks. If the account is used by a CI/CD pipeline or scheduled job, run a test deployment or trigger the job manually to confirm it has the access it needs.
Revoking Admin Permission
To remove admin access from a user or service account, open the user management interface and locate the account. Click to open their details, then uncheck or deselect the admin option. Confirm the change when prompted.
Revoking permission takes effect immediately in most systems. The user or service account will no longer be able to perform administrative tasks, though they may retain access to view or use Medal depending on their other permissions. If you want to remove all access, you may need to delete the account entirely or set their role to "None" or "Viewer" — check your system's documentation for the exact steps.
After revoking permission, consider checking the audit log (if your system maintains one) to see what administrative actions that account performed while it held access. This helps you understand what changes may need review or rollback.
Troubleshooting Permission Issues
If a user reports that they have admin permission but cannot perform administrative tasks, the most common cause is that the permission change hasn't taken effect yet. Ask them to log out completely and log back in — this forces the system to reload their permissions from the database.
If logging out and back in doesn't work, verify that you actually saved the permission change. Return to the user management interface, open that user's details again, and confirm that the admin field still shows the permission as granted. If it doesn't, the change may not have been saved the first time.
Another possibility is that the user's role or permission level is being overridden by a group or team setting. Some systems assign permissions at both the individual and group level, and a group restriction can block individual admin access. Check whether the user belongs to any groups and whether those groups have permission restrictions in place.
If you're granting permission to a service account and it still cannot perform tasks, verify that the account's credentials (API key, token, or password) are correctly configured in the application or script that uses it. A service account can have admin permission but still fail to authenticate if its credentials are wrong or expired.
Security Considerations When Granting Admin Access
Admin permission is powerful and should be granted sparingly. Before granting it, confirm that the person or service actually needs it for their role. A developer who only needs to view Medal configurations doesn't need admin access; someone who manages Medal deployments does.
Keep a record of who holds admin access and why. This doesn't need to be formal — a shared document or spreadsheet is enough. When someone leaves your team or changes roles, review that record and revoke access they no longer need.
If your system supports it, enable audit logging so that admin actions are recorded. This creates a trail of who made what changes and when, which is invaluable if something goes wrong and you need to understand what happened.
For service accounts, rotate credentials (API keys, tokens, or passwords) periodically, especially if the account has admin access. If a credential is compromised, an attacker could use it to make unauthorized changes to your Medal system.
Frequently Asked Questions
Can I grant admin permission through code or environment variables?
No. Admin permission is a user or account setting managed through your system's user management interface, not through code configuration. Attempting to set it in code or environment variables will not work and may cause errors.
What if I don't have access to the user management interface?
You need to contact someone who already holds admin access — typically your system owner, team lead, or the person who set up Medal initially. They can either grant you admin permission or make the change you need on your behalf.
Does granting admin permission require a restart or deployment?
In most modern Medal implementations, no. The permission change takes effect immediately or after the user logs out and back in. Older versions or custom setups may require a restart — check your system's documentation or ask your team.
Can I grant admin permission to multiple people at once?
Most user management interfaces require you to grant permission to one account at a time. If you need to grant it to many accounts, check whether your system supports bulk operations or scripting. Some implementations allow you to write a script that grants permission to a list of users automatically.
What happens if I accidentally grant admin permission to the wrong person?
Return to the user management interface, open that person's details, and revoke the permission immediately by unchecking or deselecting the admin option. The change takes effect right away. If you're concerned about what they may have done while they held access, check the audit log to see their actions.