in OAuth application it is possible to configure the scope only for read work items in general, non based on their projects.
is there any permission on project/user level to configure the access to specific project and restrict collection from all others?