support fine-grained permission checks in API