Amazon Quick does not expose a direct path to downgrade a user from an Admin or Author tier to a Reader tier, either through the console UI or the update-user API. Practitioners must instead rely on a delete‑and‑recreate flow or invoke the AWS CLI to replace the existing identity with a new role assignment.
Why downgrade roles matters
Applying the principle of least privilege reduces the attack surface and aligns permissions with actual job functions. In Quick, Reader accounts are billed per session rather than per user, so moving inactive authors to Reader can also lower monthly spend.
Supported downgrade mechanisms
Two reliable approaches exist for Quick‑managed users (those created directly in Quick):
- Manual recreation: Remove the user from the console and add them back with the desired Reader role.
- CLI‑driven replacement: Use the AWS CLI to delete the existing user record and register a new one with the target role.
For identities sourced from external providers such as IAM Identity Center or Active Directory, role changes are handled by adjusting group memberships in the external directory; Quick itself does not perform the downgrade.
CLI‑based downgrade workflow
Prerequisites include an AWS account with administrator rights on Quick and a configured AWS CLI. The typical sequence is:
- Identify the user’s Quick ARN and current role.
- Execute a
aws quicksight delete-usercall to remove the existing record. - Run
aws quicksight register-userwith the same identity but specify the Reader role.
Because the delete operation permanently removes the user’s ownership of dashboards and analyses, practitioners should transfer ownership beforehand to avoid orphaned resources.
Manual deletion‑and‑recreation process
When using the console, the steps mirror the CLI flow:
- Navigate to the Quick user management page.
- Select the target user and choose the delete option.
- Confirm the deletion, then use the “Add user” form to create a new entry with the Reader role.
As with the CLI method, any assets owned by the original account must be reassigned to another user to maintain continuity.
Related CloudNinjas coverage: AWS.
What This Means For Practitioners
Because Quick does not support in‑place role downgrades, teams need to incorporate explicit ownership transfer and user recreation steps into their access‑review processes. Automating the CLI sequence can reduce manual effort and ensure consistent handling of cost‑optimisation and least‑privilege goals. When external identity providers are in use, focus on group‑membership updates rather than Quick‑specific actions.


