The current access tokens should be even more granular. The current access options can pose a significant risk in some circumstances. It should be possible to a) limit tokens to specific workspaces and b) to divide the permissions further for forms and feedback.
