Hi I have posted a havana blueprint for an extension to domain roles that would solve one of the issues that has arisen by the move to RBAC in the keystone v3 identity API - that of the lack of a "super user admin role". This proposal attempts to solve the actual issue within RBAC, rather than simply recreating such a super admin. https://blueprints.launchpad.net/keystone/+spec/inherited-domain-roles Comments welcome. Henry