We should ship an authorization provider that check for permissions based on PHPCR capabilities and access controls