My app is a multi-tenant solution which I have set up so that clients can maintain their own users. I have an Access Level called client admin which is for basic system administration, then there is the Aware default 'Administrator' access level. I currently prevent them from giving themselves Administrator writes by removing it from the pick list options. This has 2 limitations:
creating a new admin account for someone on my staff required adding the value in, publish, create the admin account, deleted the value, republish
Using the Loggin In User report does not work due to failure to update the admin user since the value is not on the valid list of choices.
My idea was to leave the Administrator Value in place, but add a hidden seperator with a 'code' field. Then add a rule along the lines of i.e. If Access Level = Administrator AND Code <> 12345 then AccessLevel=UserAdmin.
So my question is... am I using a sledge hammer to swat a fly? Is there a better way to do this?