Our suborg admins would like to be able to impersonate users within their suborg. We have those permissions turned on for that role, but realized we likely need to have the permissions turned on for the learner role as well, since that is how suborg admins are enrolled at the org level.
While we don't want learners to be able to impersonate other users, they don't actually seem to see any links or menu items that would allow them to do this, even with the permissions turned on, so that's ok. However, our suborg admins don't seem to be able to impersonate users unless we also turn on some of the impersonate permissions for the instructor role.
This then also gives instructors the ability to impersonate any user enrolled in one of their courses, which poses a security risk, since they are then able to see the content of any other course that user is enrolled in.
We're not sure why permissions at the instructor level are needed for this to work, and are wondering if there is a way around this that would allow the suborg admins to impersonate without also giving that ability to instructors?