Hi,
I created a new user which has access to only a test network and using the API I cannot access network listing as the API Key generated does not have organization access, so cannot list networks in organizations. But if I give Organization Read access to this user I can list ALL the networks and I could read, for example, the firewall configuration on every network as the user has read access although I specified only one network access.
I think this is a big problem for every external application using the API in terms of security as it is not possible to give access to only one network without giving organization read access.