According to this, you can configure deployment permissions for each environment individually. However, any developer can simply push a change to the bitbucket-piplines file in a different branch (like in a branch that is defined as a test deployment) and switch it to deploy to production. How can you prevent this? Basically it makes the whole feature useless from a security perspective...