# Accidentally granting admin access

**URL:** https://meta.discourse.org/t/accidentally-granting-admin-access/206410
**Category:** Support
**Created:** [October 9, 2021, 3:36am UTC](https://meta.discourse.org/t/accidentally-granting-admin-access/206410 "2021-10-09T03:36:18Z")
**Posts on this page:** 1
**Showing post:** 4

<div class="post-metadata">

### Author: ![jomaxro](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/jomaxro/32/126216_2.png) [@jomaxro](https://meta.discourse.org/u/jomaxro)
#### Post date: [October 19, 2021, 3:59am UTC](https://meta.discourse.org/t/accidentally-granting-admin-access/206410/4 "2021-10-19T03:59:43Z")

</div>

We can’t protect admins from shooting themselves in the foot. If a non-trusted user gains admin access, for any reason, all bets are off. The site should be considered compromised. The site owner should follow [What to do if your Discourse is compromised](https://meta.discourse.org/t/what-to-do-if-your-discourse-is-compromised/40129).

2 notes.

1. Granting admin access isn’t as simple as just clicking a button. After clicking the “grant admin” button, one must receive a link via email to finalize the process. It is unlikely that an admin grants admin access accidentally.
2. Even if a malicious actor has admin access on a Discourse forum, that access doesn’t grant server access. The site owner would still be able to take action via the console on the server.

* * *

This discussion seems to have gotten off topic though. Accidental or malicious admin access doesn’t have anything to do with the moderation guide. I’m going to move this to a new topic.

---

_[View the full topic](https://meta.discourse.org/t/accidentally-granting-admin-access/206410)._
