Problem
API and OAuth tokens currently have very wide permissions across all resources, such as the 'Shared Resources' scope allowing read+write access to all shared resources.
Request
Support more granular scopes for API tokens and OAuth tokens, such as read-only or write-only access per resource type (conversations, contacts, etc.).
This could also apply to admins choosing which specific workspaces an application authorized through OAuth has access to versus granting access to all workspaces and resources