Customers working on an automated framework to onboard new Teams into Konnect leverage a service account with privileges in Konnect to do things like create a Runtime Group, setup Teams, Role mappings, etc. In particular, they need the ability to create Runtime Group and pin certificates for the dataplane. Today, doing this requires Organizational Admin entitlements in Konnect which customers do not want to grant to service accounts.