Web and API - Save User and View User API - Get user info should return facility access - Restrict access to endpoints which the user shouldn't be able to access