Event Summary
User account dnguyen@dreamstechnologies.com was granted the Org Administrator role outside of the standard access-request workflow. The change was applied directly via the Admin API and bypassed the two-person approval policy required for privileged role grants. The system flagged the event automatically based on anomalous privilege-change velocity.
Changed Fields
| Field | Before | After |
|---|---|---|
| Role | Editor | Org Administrator |
| Scope | Workspace: Marketing | Workspace: All (Global) |
| MFA Requirement | Enforced | Not Enforced |
| API Key Access | Read-only | Read / Write / Delete |
Event Timeline
Case moved to Under Review by Amelia Hart
Today, 10:41 AM · Security Team
High-risk alert dispatched to #sec-alerts and on-call responder
Today, 10:26 AM · Detection Engine
Anomaly detected: privileged role granted without approval
Today, 10:24 AM · Detection Engine
Role change executed via Admin API by dnguyen@dreamstechnologies.com
Today, 10:23 AM · API token svc-admin-04
Related Audit Events
Evidence & Attachments
raw_api_request.json
4.2 KB · Captured 10:23 AM
access_policy_snapshot.json
2.8 KB · Captured 10:24 AM
session_screenshot.png
318 KB · Captured 10:25 AM
network_trace.pcap
1.1 MB · Captured 10:24 AM
Investigator Notes
Amelia Hart · 2 hours ago
Confirmed the role change did not go through the approval workflow. Reaching out to D. Nguyen's manager to confirm intent before revoking access.
Marcus Lee · 40 minutes ago
Admin API token svc-admin-04 has been temporarily suspended pending review.
Actor
View ProfileRole: Editor (pre-event)
18 events in last 30 days
Employee since Feb 2023
Device & Network
IP: 203.0.113.44 (Unrecognized)
Bucharest, Romania
Chrome 126 on Windows 11
Device ID: fp_9a21c8e0
Affected Resource
Workspace: Dreams Technologies – Production
Resource: IAM Role Binding
Resource ID: role-bind-7f21ac
3 downstream resources impacted