You would need to develop this functionality into blesta, or create your own API. Currently the blesta api offers full access to all functions of blesta so your customer would have access to everything, including other customers data. Administrators do not have have granular controls on what access API users have at the endpoints, and probably never will due to the way the blesta api works.