We have spaces that have content classification and restrictions.
We would like space owners/administrators to still have control over permissions within these spaces, but we need to limit the "pool" of users they can add to the space to a specific group or groups.
I'm fully aware that they can simply add "allowred users" group as a group in the permissions settings to enable access to all users of that group. That's not what I'm after though.
I need to ensure they don't add "Bob", who's not a member the "allowed users" group to the space, thus bypassing content access controls.
I don't think there's a way of doing this, nor have I seen any plugins that do this. I figured I'd ask here, as I'm sure others have come across content classification needs.
The only solution I've come up with so far, is to simply not allow space owners admin control, and farm out all permission work to a trusted team on a request model. That's going to add additional delays to users gaining access to content, since that team will be required to vet the request through the space owner. The space owner knows best, but for compliance reasons, we need to remove the possibility of the owner adding someone they're not allowed to.