The problem
System-wide configurations are all-or-nothing: anyone who can reach the configuration view can see and change every one of them. Some settings are ordinary operational knobs, and others — credentials, integration endpoints, limits with billing consequences — are not.
What we have in mind
Per-configuration security constraints, so that visibility and editability can each be restricted to a set of roles. A configuration a user cannot edit should be visible read-only or hidden entirely, depending on how it is declared.
Opened from our own backlog when this tracker went public. If you need this, say so — comments and concrete use cases are what move something up the list.
The problem
System-wide configurations are all-or-nothing: anyone who can reach the configuration view can see and change every one of them. Some settings are ordinary operational knobs, and others — credentials, integration endpoints, limits with billing consequences — are not.
What we have in mind
Per-configuration security constraints, so that visibility and editability can each be restricted to a set of roles. A configuration a user cannot edit should be visible read-only or hidden entirely, depending on how it is declared.
Opened from our own backlog when this tracker went public. If you need this, say so — comments and concrete use cases are what move something up the list.