Originally Posted by
WineCountryUA
Not sure what you mean by "allowed" -- you can do it and there is essentially no way to trace who did it(except by IP address which is not useful in many cases)
Such as
Unauthorized flight reservation change made by someone else
This issue has been discussed many times and it is a needed feature for those that have others manage their travel. But it can be misused -- hence treat your PNR / BP with respect
And yes the scammers use this feature.
Modern enterprise software that allows users to delegate authority to others (admins) generally implements that in such a way that it isn’t via essentially anonymous access. Audit and access control is a strict requirement. Airlines could certainly implement that if they wanted to.