Fine grained access control on specific watchers

I want different users to create and manage their own watchers.
A user could edit / create / delete / ack only the watchers he created.

I noted watcher privileges are of type "cluster", so basically each watcher admin could edit / delete watchers created by other users.
Is there a way to restrict it?

Moreover, is it possible to associate "ack" permissions to specific users and to specific watchers, but not create/delete permissions?
Thank you


the security model right now does not allow for this. You either have watcher admin privileges to do everything or not, but there is nothing in between.


thank you @spinscale. Do you have plan to add this feature in later versions? I haven't found any related open issue.

