split "System Admin" into "Configuration Admin" and "Content Admin"

hi

this probably is a feature request for M-Files but actually I'm hoping more for someone having a solution which already works.

Our problem: we have multiple use cases where the users administring M-Files are not allowed to see [all] content of the vault.
The most typical use case is HR-Data which is protected by GDPR and nearly nobody (except HR and the corresponding person) should see this.
As you may know, System- and vault admin see all content of a vault which goes in contra of this content.
So we would love to have a type of admin who can use only M-Files Admin but not M-Files client.

We are aware of the "Administrative rights in vault" where you can enable a user to manage meta data, workflows etc. but this lacks big parts of M-Files admin, like:

- connection to external databases
- Metadata card configuration
- configuration of VAFs (and also the ability to install/update VAFs)

anybody has an approach to this?