Discuss and decide all areas for restricted access (high granularity)
We know that we don't want any users attaching or detaching implementations or testes unless they are sysadmins, but we should probably make the exercise of checking what other ZObjects (and parts of ZObjects) should be restricted and to whom.

This task is to drive the conversation, documentation and decision of what granular sub-ZObjects need to be restricted and to whom.

Completion checklist