Hello @dchiesa1
We have a single Apigee organization with multiple dedicated environments. Different user groups should only be able to view and manage the resources and developer applications within their assigned scope, while central administrators should retain access across all environments.
Environment-level segregation is working for several resources, but we are unable to achieve the same for developer applications.
We tried using:
Custom IAM roles
Resource-level permissions
IAM Conditions
Resource-name-based restrictions
After applying IAM Conditions, the Applications page remains stuck in a loading state, with no applications displayed and no clear authorization error.
Could you please confirm:
Is developer application-level segregation supported within a single Apigee organization?
Can developer apps be restricted using IAM Conditions, resource names, tags, developer identities, or other supported attributes?
If supported, what minimum IAM permissions are required for the Applications page to load correctly?
If this is not supported, what is the recommended architecture for strict application-level isolation?
Any recommended IAM example or supported approach would be appreciated.
Hi @Izza_Fatima, welcome to the Apigee Community, we are thrilled to have you here!
We have seen your question and want to assure you that it is in the right place. In the meantime, we invite our community members to jump in and share their thoughts, approaches, or experiences!
Since you are building with Apigee, I would also love to invite you to our upcoming Community TechTalk this Thursday, July 23, 2026: Apigee AI Portals for Model, Tool & Agent Self-Service. We will be exploring how to turn traditional portals into full-scale, self-service neural hubs for enterprise AI interactions.
Apigee AI Portals for Model, Tool & Agent Self-Service
Speaker: Tyler Ayers
Date: Thursday, July 23, 2026
Time: 9:00 AM CST (Mexico City) | 11:00 AM EDT (New York) | 12:00 PM BRT (SĂŁo Paulo) | 5:00 PM CEST (Berlin)
Application-level segregation within a single Apigee organization refers to logically separating APIs, environments, and access controls for different apps or teams—improving security, governance, and scalability without needing multiple organizations.