Sure feel free to leave comments on the issue ( or file a PR against
that document and I will try to incorporate it.

Thanks for the response!

+1 on the "bosh-director.DIRECTOR-UUID.admin" scope. I assume this means
that in the event of multiple directors, users will have to have multiple
scopes associated to their credentials (either through uaa or local). That
would be a great start.

Is there anyway i can follow/vote on the items regarding authz? I like the
proposed scope schemes to create some ACL control. I'm hoping to use BOSH
as a viable tool to empower datacenter operators. As this is defined, the
idea or different roles is essential. (Are pull request welcomed?)

