Granular permissions through roles and overrides
I'm not sure about readable API keys/credentials under Credentials. While extremely useful, without granular permissions, this is also a huge security risk. Extending on https://feedback.simplemailservice.eu/feedback/212888, it would be great to also assign users: The possibility to register new domains, which they will then have ownership off. Only if someone owns a domain, they can access the credentials. I'd say that, especially when API keys/SMTP credentials are scoped (https://feedback.simplemailservice.eu/feedback/212887), it's fine for all users to see which domains are available under the account and who owns these. The same can be applied for other sections too. One user might be able to create domains, but would have no reason to create webhooks and such. More importantly is probably fine grained control over who can read "Messages" and which type. I'm aware this is very impactful, but can be rolled out in granular way too. Eg. While it would be really cool if you can give someone "Add Credential" permission, but they can then only assign those credentials to domains they actually have ownershop off, that is something that could be added much later. Currently, just disabling the functionality for some user (roles) is enough. Best step foward is probably to create some kind of permission matrix and work from there. Just to reiterate on my use case: Critical While I trust my employees, everyone being able to see all credentials feels wrong. The ability to recover created credentials should be a super admin level permission. Nice to have Same goes for adding domains and adding credentials (these two go hand in hand: for me one can't go without the other): this permission should be reserved for some users, while it's okay for everyone to see which domains exist. Nice to have Disabling all other functionality, except for Messages for all would be great. Or rather and opt-in: I can decide what users can access. Meaning that new functionality that gets added by SeS, won't be automatically available to users. Important From a privacy perspective: Disable viewing e-mail data for specific users, while allowing to see the metadata (for debugging purposes).