Use a json field for access level controls. Send ACL to client and verify controllers sever-side follow ACL with correct policies.