permission api should be clearer+priority