Grant access to users at a resource level of granularity, rather than just project level. For example, you can create an IAM access control policy that grants the Subscriber role to a user for a particular Pub/Sub topic.
Using Recommender, you can automatically detect overly permissive access and rightsize them based on similar users in the organization and their access patterns.