Is there an ETA when ALL other access rights can be assigned separately by customers to support least privilege.
In addition, identities with ORG_ADMIN capabilities can read and write objects, even for newly introduced object types.
Can you create a ORG_READ_ADMIN user level that, when we assign it to someone; they will automatically be able to read all objects that org_admins could read as well, including future object types (and only write them if allowed in other ways). So we shouldn’t have to update our stuff each time a new object type is introduced. (This last request is the most popular request as you can see in the idea portal)