Currently namespace-scoped users can access their unauthorized namespaces indirectly via Consumer. Perhaps better with webhook for authorization.