In my organization settings when I invite a member in addition to assigning them a role it would be most helpful to also have an option to select which servers they have access to.
and perhaps other feature flags to enable disable access to other areas of the OCC
We have individual user based access to servers on our list (probably through some sort of “team” based structure so you can assign groups to servers).
We have a similar feature for projects in mind as well.
For the sso/cloud storage I can see not wanting people to make changes, but you want to completely hide it from them? Is this a case where you need them to have full access to some servers but not to all features on the org? ie. you need to give them admin level access but don’t want them to fuss with SSO or with storage?
What’s the use-case for not wanting them to have access to the tools page?