In order to differentiate access to data it seems that one currently has to define different services with different access rights. However, having e.g. a service per project would be quite cumbersome and I have no idea if it would be possible to make data available across services (in case access constraints are removed)...
It would be good to be able to distinguish access rights within a service (e.g. specific sensors are only visible for different users / roles), e.g. at offerings or procedure level?
For related discussion on ML, see:
https://groups.google.com/forum/#!topic/istsos/NAMGUxQWIE4