Unfortunately, there is currently no way to restrict issue creation in that way. Every user having at least the “Run Executor” role is allowed to create/link defects.
We do have a more granular permission & role system as a feature request in our roadmap already. Still, I moved this as feature request to the App Feedback category in this forum so others can also vote for it.
If somebody reads this request and would also like to have this feature, make sure to vote for this topic. We do consider the number of votes for feature requests in our roadmap and priority planning.
This should now be possible at least with Jira integrations:
With the new OAuth Jira connection, you can require users to link their own Jira account for issue/defect creation. So only users with a valid account on the Jira organization/project linked to Testiny, can create new defects/requirements via Testiny.
See the following page in the Testiny Docs for more info: