The risky part is not the button. It is the missing review.
- Troubleshooting project access without checking product access first
- Changing a shared permission scheme without impact review
- Using groups and project roles interchangeably
- Ignoring global permissions when a user has broad power