There should be an option to disable creation of tokens and/or allowing token generation to a certain set of users only until we have granular controls in place?
Admins should be able to centrally manage tokens, revoke if required. This is useful when there is a suspected token leak. Especially when the API is hosted outside of Atlassian with no Ip Firewall, an adversary can exploit the situation. Can also be done by an ex-employee.
| Tempo Products | Other |
| Tempo Platform | Cloud |