It is very important to ensure we willingly grant access to users’ permission to create groups and organizations especially for MSSPs. At the moment a low-level user is able to create multiple groups, multiple organizations, grant those groups full permissions, and still view billing which is already restricted for them.
Worrying this infrastructure is not natively visible to the MSSP organization admins.
It is important however to scope the potential impact of this. Although it’s true a user could create these things, the permission system would not allow them to gain any higher permissions on other existing orgs in your MSSP. So they could create test orgs, put whatever they want in it, but not gain access to anything else. So from a data sensitivity it’s a bit like the sound of one hand clapping.
The only real potential impact could be for billing purposes, meaning they could create an org and set a quota that would be billed up to your MSSP (only if Unified Billing is enabled on your domain).
We will let you know when the new higher level object for MSSP is available (name is still TBD).