Thanks.
Would you'd mind expanding more on "An operator permission granting is a great fundamental layer to add here"
I am not sure I understood correctly (apologies in case).
If I am tenant admin, and I have been given by platform admin full permissions, but only in a namespace/cluster. Then if I install an operator in this namespace/cluster, at most this operator can only have same permissions I have, not more. If operator requires more, tenant admin has posting operator itself will fail (pure Kubernetes RBAC)