Role permissions to only allow user impersonation on the subtenants users

Renato @Censi I met with Product this week; this capability hasn’t progressed on the priority list yet; but, while we are having the discussion, is something like this what we are thinking?

@wabbas / @EdwardVanHazendonk would this also work for your architectures?