Org membership is currently all-or-nothing, any member can access every project in the org, and RBAC roles gate actions, not project visibility.
Customers with mixed-sensitivity workloads need to restrict which projects a given user can access without splitting them into separate organizations.
