We have multiple platform teams working on top of our Azure foundation platform.
We want these platform teams to use the "Platform Builder" to manage their own landing zones using the "Landing Zone Contributor" feature.
Now the platform team wants to also import existing subscriptions into meshStack. However, today this is an admin level permission that cannot be scoped to
  • allow import only into landing zones owned by the platform team
  • allow import only of subscriptions that are supposed to be "owned" by that platform team
These restrictions are necessary so that the platform team cannot put meshStack into a "confused deputy" situation where it would use the replicator to arbitrarily adopt subscriptions that the platform team should not have control over.