This task is for implementation of the Enforcement section of T419622: Verify GrowthBook access approach parts 1-3.
This should be done first for growthbook-next.wikimedia.org to confirm proper function, then for growthbook.wikimedia.org.
This depends on completion of T420690: Create Project in GrowthBook, then migrate materials and access to it and T420688: Create new Wikimedia IDM ("Bitu") LDAP groups for GrowthBook for economy, although technically it would be possible to try it out without the Project first, and then shift it to have the Project confinement notion second.
This is being dropped into Sprint 21 (it will be DP SRE work) for work tracking, but may be dragged into a subsequent sprint.