Drupal is a registered trademark of Dries Buytaert
Search API Solr 4.4.0 Minor update available for module search_api_solr (4.4.0). Page Manager 8.x-4.0 Major update available for module page_manager (8.x-4.0). Trash 3.1.0-beta2 New beta version released for module trash (3.1.0-beta2). Commerce AutoSKU 3.0.1 Minor update available for module commerce_autosku (3.0.1). Custom Field 4.0.10 Minor update available for module custom_field (4.0.10). Alternative login ID & display names 2.0.12 Minor update available for module alt_login (2.0.12). EntityReference UUID 3.0.1 Minor update available for module entity_reference_uuid (3.0.1). LocalGov Publications Importer 1.1.1 Minor update available for module localgov_publications_importer (1.1.1). Configuration Override Warn 8.x-1.6 Module config_override_warn updated after 10 months of inactivity (8.x-1.6). Table Alternate Rows Module table_altrow crossed 1,000 active installs.

Role Audit

73 sites Security covered
View on drupal.org

Role Audit helps you visualize and compare permissions and route access between different Drupal roles. It highlights which access rights are unique to each role or shared, aiding in security analysis and conflict resolution.

Role Audit provides a visual comparison of permissions and route access between different Drupal roles. Easily identify overlapping or unique access rights using a logic-driven interface similar to a Venn diagram.

Features

Managing complex access control in Drupal can be opaque. Role Audit simplifies site governance by allowing to compare two or more roles side-by-side to understand exactly where access levels diverge.

  • Permission Comparison: Quickly see which permissions are unique to Role A, unique to Role B, or shared by both.
  • Routing Audit: Analyze static routing definitions to see which roles have access to specific system paths.
  • Security Gap Analysis: Identify risks where a "lower" role might accidentally have more power than a "higher" role.
  • Conflict Resolution: Perfect for debugging why a specific user can or cannot perform an action based on their assigned roles.

Post-Installation

Once installed, navigate to People > Role Audit (/admin/people/role-audit), where you will find two primary tools:

  1. Permissions Audit: Select your roles to generate a filtered table highlighting the differences and commonalities in their permission sets.
  2. Route Audit: Compare how different roles access system routes based on static definitions.

Disclaimer: The Route Audit examines static routing definitions (e.g., _permission and _role). It does not account for dynamic access checks or custom AccessCheck services. For a 100% accurate vision of access, always test specific routes with specific parameters for each user role.

Additional Requirements

  • This module relies solely on Drupal Core (User and Routing modules) and has no external dependencies.

Activity

Total releases
3
First release
Mar 2026
Latest release
3 weeks ago
Releases (12 mo)
3 ▲ from 0
Maintenance
Active

Release Timeline

Releases

Version Type Release date
1.x-dev Dev Jul 7, 2026
1.0.1 Stable Apr 9, 2026
1.0.x-dev Dev Mar 9, 2026