Inherited permissions repair

Asha must read and amend assigned reports, but cannot delete the archive or change permissions. Repair the effective permission set.

WORKED REASONING
In this exercise grants are additive and there are no deny rules. Remove Asha’s unintended Archive-admins membership; preserve Analysts. Removing a direct delete grant alone would leave the group grant effective. Verify read and edit success, archive deletion refusal and permission-change refusal after refreshing the stated authorization context. Changed fact: a separate direct delete grant is also active. Removing administrator membership now leaves deletion allowed. Remove that unwanted direct grant too, preserve required read and edit, refresh the context and repeat all four tests.

These records and settings are fictional. The rule model is stated for teaching; actual product documentation governs real configurations.
