permission api should be clearer+assigned to