I think we should track which users have "trusted" roles on a site and send an e-mail whenever that list changes. The e-mail could include all users in those trusted roles.

The reason to do this here rather than somewhere else (like paranoia) is that security_review has a concept of "trusted roles" and settings for it already.

Comments

coltrane’s picture

So far we a "review" section and I was thinking of a "recommendations" part #906726: Recommendations system so there could be a part of the module (tab?) that allows for tracking specific checks (when they change) and could also allow for other tracking like this.

greggles’s picture

I'm starting to think this might belong more in something like paranoia (if killes is willing).

greggles’s picture

Issue summary: View changes
Status: Active » Fixed

Status: Fixed » Closed (fixed)

Automatically closed - issue fixed for 2 weeks with no activity.