I have a requirement where I want to restrict certain service account from creating key (json/yaml file) but that restriction should only affect specific service account in a specific project which belongs to an organization.
I did go through the following documentation, but It did not match the requirement of restricting only certain service account rather than all service account in that particular organization.