hi. @Paul-Winterhalder
yes, permissions to call specific scripts and access control for Services and Operations regarding the generally provided functions are required.
For example, there may be management tools that call specific scripts and use certain functions (CloudData...),
and there may be administrators who only manage items.
If possible, each API Key should be a function with permissions tailored to the situation.
Let me give you an example. A company utilizes a mix of office and remote work. While the internal network can be protected to some extent by IP ranges, it is difficult to identify specific IPs because multiple operators work from home. Therefore, it is currently somewhat difficult to handle this situation using only IPs.