Limit the permission scope to read workspaces, read templates, template versions, buildinfo, read/write workspace, agents + apps, read your own user details, authentication, read access to SSH keys
This can be fully addressed once coder/coder#21631 is implemented