been thinking about how to selectively declare access control policies as granular and as narrow as a single fact, wish i had an answer
read an article that basically concluded the document centric model and rest architecture is insufficient for this unless you put one fact per document which is patently ridiculous
the other thing is where to even put those documents. some resources ought to be dynamic views, or possibly all documents can be thought of as views but to some extent hardcoded