Add "Credential Inventory API" as customizable permission

Everyone can contribute. Help move this issue forward while earning points, leveling up and collecting rewards.

Problem to solve

The current credential inventory API requires top-level group ownership permissions, forcing organizations to grant overly broad access to security teams who only need credential management capabilities. This conflicts with the principle of least privilege and creates operational challenges for enterprises where security teams need credential oversight without full organizational administrative access.

Proposal

Create a custom role for the credential inventory API on GitLab.com

Edited by 🤖 GitLab Bot 🤖