Live
npm Trusted Publishing Configurations Auto‑Expire After 48 HoursZero‑Trust Network Automation with Ansible: Adjusting Architecture and OperationsOpenAI Codex Sprint Raises Token Throughput and Resets Usage Limits – Practical Implications for EngineersHandling Quick Role Downgrade: CLI and Re‑creation Strategies for Secure Access ManagementEnabling OpenAI Text Watermarking in the API: Operational Impact and Compliance ConsiderationsOperationalizing Multi‑Agent Explainability with Amazon Bedrock AgentCore EvaluationsDynatrace integrates Arize’s AI observability into its monitoring platformEnabling Node Swap in Kubernetes 1.34: Practical Impact on AI‑Heavy Workloadsnpm Trusted Publishing Configurations Auto‑Expire After 48 HoursZero‑Trust Network Automation with Ansible: Adjusting Architecture and OperationsOpenAI Codex Sprint Raises Token Throughput and Resets Usage Limits – Practical Implications for EngineersHandling Quick Role Downgrade: CLI and Re‑creation Strategies for Secure Access ManagementEnabling OpenAI Text Watermarking in the API: Operational Impact and Compliance ConsiderationsOperationalizing Multi‑Agent Explainability with Amazon Bedrock AgentCore EvaluationsDynatrace integrates Arize’s AI observability into its monitoring platformEnabling Node Swap in Kubernetes 1.34: Practical Impact on AI‑Heavy Workloads
AWS

Handling Quick Role Downgrade: CLI and Re‑creation Strategies for Secure Access Management

AI SummaryPowered by AI

Amazon Quick lacks a direct downgrade path for Admin or Author users, requiring deletion and recreation or CLI‑based replacement to assign a Reader role. This impacts cost control and least‑privilege enforcement for engineers managing Quick environments.

Amazon Quick does not expose a direct path to downgrade a user from an Admin or Author tier to a Reader tier, either through the console UI or the update-user API. Practitioners must instead rely on a delete‑and‑recreate flow or invoke the AWS CLI to replace the existing identity with a new role assignment.

Why downgrade roles matters

Applying the principle of least privilege reduces the attack surface and aligns permissions with actual job functions. In Quick, Reader accounts are billed per session rather than per user, so moving inactive authors to Reader can also lower monthly spend.

Supported downgrade mechanisms

Two reliable approaches exist for Quick‑managed users (those created directly in Quick):

  • Manual recreation: Remove the user from the console and add them back with the desired Reader role.
  • CLI‑driven replacement: Use the AWS CLI to delete the existing user record and register a new one with the target role.

For identities sourced from external providers such as IAM Identity Center or Active Directory, role changes are handled by adjusting group memberships in the external directory; Quick itself does not perform the downgrade.

CLI‑based downgrade workflow

Prerequisites include an AWS account with administrator rights on Quick and a configured AWS CLI. The typical sequence is:

  1. Identify the user’s Quick ARN and current role.
  2. Execute a aws quicksight delete-user call to remove the existing record.
  3. Run aws quicksight register-user with the same identity but specify the Reader role.

Because the delete operation permanently removes the user’s ownership of dashboards and analyses, practitioners should transfer ownership beforehand to avoid orphaned resources.

Manual deletion‑and‑recreation process

When using the console, the steps mirror the CLI flow:

  1. Navigate to the Quick user management page.
  2. Select the target user and choose the delete option.
  3. Confirm the deletion, then use the “Add user” form to create a new entry with the Reader role.

As with the CLI method, any assets owned by the original account must be reassigned to another user to maintain continuity.

Related CloudNinjas coverage: AWS.

What This Means For Practitioners

Because Quick does not support in‑place role downgrades, teams need to incorporate explicit ownership transfer and user recreation steps into their access‑review processes. Automating the CLI sequence can reduce manual effort and ensure consistent handling of cost‑optimisation and least‑privilege goals. When external identity providers are in use, focus on group‑membership updates rather than Quick‑specific actions.

Originally published atAWS Machine Learning Blog