A user at account level is able to be granted privileges at a lower scope but this isn't the case with Service Accounts. It would be great to allow say an Account level Service Account to be granted RBAC at Orgs or Projects without needing a complex Resource Group configuration. Right now we only need a service account to be able to access a single shared secret at account level which means it must be vended there but the rest of the privileges are scoped further down. being able to add these roles at the actual acope would be much better than limiting via resource group