Currently you can change your permission type to a higher level of permissions. We would like that to be restricted. Example: If I'm a local admin, I can change myself to Corporate admin so I have more access. Same thing for all the permissions type.
In our case, we have support staff that needs to edit site users. We still need the support staff to edit site users but not have the ability to change their own permissions.
Yes, we can definitely handle that now.
Can't you restrict users by not giving them permission to edit site users?
I can definitely see the value in this. The challenge is that our permission types are configurable and not hierarchical, so it's difficult to determine which permission types are higher than others. However, this is worth looking into. There might be something we can do.