I’m trying to enforce a strict access control model in my Jira Cloud site
Only Org Admins (group: org-admins) should be able to change project/space access and permissions.
Other project admins (including test admins / team leads) must not be able to change access.