pulumi / pulumi-cloud-requests

Welcome to the public issue tracker for Pulumi Cloud (app.pulumi.com)! Feature requests and bug reports welcome!
10 stars 4 forks source link

Fine grained permissions for organization tokens #446

Open o-l-a-v opened 3 months ago

o-l-a-v commented 3 months ago

This feature request exists for users, but not for organization tokens:

Currently, organization tokens are either "member" or "admin":

If one were to use an organization token for fetching audit logs using the audit log API:

One would have to add admin permissions to the token:

This does not follow the concept of least privelege.

Affected feature

Please implement the ability to give granular / fine grained permissions to org tokens, like only having the ability to read/get audit logs.

Examples: