Restore Project Roles When a Project Deletion Is Denied
T
Tobias Altendorf
When a project deletion is requested, meshStack immediately removes every user and group role assignment on the project. If an administrator then denies the deletion, the project returns to active and its tenants are reinstated — but the roles are not. The project comes back empty, and someone with workspace-level rights has to add every member again by hand. They also have to know who held which role beforehand, since nothing in the restored project records what was there.
We'd like a denied project deletion to leave the project exactly as it was before the request:
- Roles restored — every user and group role assignment on the project is reinstated, with its original role and expiry date
- Cloud access restored — the reinstated assignments are replicated, so application teams regain access to the project's tenants in the cloud platforms
Janny the AI Product Manager
Thanks for taking the time to write this up — this is a really clear and thoughtful request.
Totally understand the pain here: if a deletion gets denied, having the project come back without any of its prior role assignments (and no record of what they were) creates a lot of manual work and risk.
We’ll share this with the team. A couple quick clarifiers to help us capture the expected behavior precisely:
- When the deletion is requested, do you want roles to remain in place until the deletion is approved, or is it fine to remove them immediately as long as they’re fully restored on denial?
- Should the restore include allassignment metadata (e.g., expiry dates, justification/reason fields if used), or only role + expiry?
- For “cloud access restored”: are there specific platforms where the replication gap is most painful for you, or is this across all connected tenants?
If you can share an example scenario (even anonymized) of the roles/groups on a project before deletion, that would help us validate edge cases.