Granting Test and Manage Updates Permission
The Test and Manage Updates Joomla ACL action lets you delegate one defined QCUL capability without automatically granting every laboratory or production operation.
What this permission controls
Test and Manage Updates allows an authorized Joomla user group to create or refresh the laboratory, test updates, and continue paused laboratory work. QCUL checks permissions server-side; hiding or showing a button is not the security boundary.
Grant it through Joomla ACL
- Open System → Global Configuration or the QC Update Laboratory component permissions screen, depending on how you manage component ACL.
- Choose the Joomla user group that should receive the capability.
- Set Test and Manage Updates to Allowed for that group, taking inherited Denied rules into account.
- Save the Joomla permissions and test with an account that belongs to the intended group.
Keep the scope narrow
For Test and Manage Updates, grant only the capability required for that maintenance role. A technician who needs narrower access should receive the corresponding focused permission rather than broad component authority. Production push and production rollback are even stricter: current 1.01.14 requires a Joomla Super User with the required QCUL operation permission.
Defense-in-depth principle
Granting Test and Manage Updates Permission is one layer in QCUL’s security model. Keep Joomla ACL, CSRF tokens, private gate/storage, laboratory identity, runtime authorization, side-effect quarantine, production Super User checks, and careful handling of production-derived evidence together rather than weakening another control to make one workflow more convenient.
Community Discussion
Want to compare update-testing workflows, share practical tips, or discuss how you use this QCUL feature? Visit the QC Update Laboratory Community. For private support, bug reports, account-specific issues, or feature requests, use the QuantaCade support system.