Hey, I looked through the open feature requests on https://jira.atlassian.com/secure/Dashboard.jspa and I couldn't find anything like this - but maybe it's there.
As an admin, I can currently allow or disallow users to generate personal API tokens via authentication policies. That is, I can turn it on or off, and I can limit how many days before the token expires.
Additionally, when users create these tokens, they can choose the scopes.
What I would love to see is the ability for me as admin to limit the scopes my users have available to them.
With the advent of generative AI tools, it's much easier to use the API, and I'm worried about well-meaning users accidentally deleting or modifying data. I would prefer to limit the majority of people to read-only scopes.
Has anyone else found a workaround, or do you see this as a feature request we can upvote?