Application-level segregation within a single Apigee organization

Hello @dchiesa1
We have a single Apigee organization with multiple dedicated environments. Different user groups should only be able to view and manage the resources and developer applications within their assigned scope, while central administrators should retain access across all environments.

Environment-level segregation is working for several resources, but we are unable to achieve the same for developer applications.

We tried using:

  • Custom IAM roles
  • Resource-level permissions
  • IAM Conditions
  • Resource-name-based restrictions

After applying IAM Conditions, the Applications page remains stuck in a loading state, with no applications displayed and no clear authorization error.

Could you please confirm:

  1. Is developer application-level segregation supported within a single Apigee organization?
  2. Can developer apps be restricted using IAM Conditions, resource names, tags, developer identities, or other supported attributes?
    If supported, what minimum IAM permissions are required for the Applications page to load correctly?
  3. If this is not supported, what is the recommended architecture for strict application-level isolation?
    Any recommended IAM example or supported approach would be appreciated.

Hi @Izza_Fatima, welcome to the Apigee Community, we are thrilled to have you here!

We have seen your question and want to assure you that it is in the right place. In the meantime, we invite our community members to jump in and share their thoughts, approaches, or experiences!


Since you are building with Apigee, I would also love to invite you to our upcoming Community TechTalk this Thursday, July 23, 2026: Apigee AI Portals for Model, Tool & Agent Self-Service. We will be exploring how to turn traditional portals into full-scale, self-service neural hubs for enterprise AI interactions.

Apigee AI Portals for Model, Tool & Agent Self-Service

  • Speaker: Tyler Ayers

  • Date: Thursday, July 23, 2026

  • Time: 9:00 AM CST (Mexico City) | 11:00 AM EDT (New York) | 12:00 PM BRT (SĂŁo Paulo) | 5:00 PM CEST (Berlin)

Register now for the Community Techtalk :right_arrow: Google Cloud Apigee Community TechTalks

We hope to see you there, and we’ll keep an eye on this thread to ensure your question gets the attention it deserves!

Hi @Izza_Fatima Have you tried using Apigee Spaces? Apigee Spaces overview  |  Google Cloud Documentation

Application-level segregation within a single Apigee organization refers to logically separating APIs, environments, and access controls for different apps or teams—improving security, governance, and scalability without needing multiple organizations.