What we are trying to achieve is to be able to give permission to users to clone,create,destroy VMs over the API in their only pool only. So the goal is they see and do only what is in their own pool. We have achieved that in the UI as giving them permission to:
Path Role...