Instead of listing all permissions define under the original Resource type, the API should report the applicable permissions for this kind of resource given it resides under a specific service type, which can enforce specific permissions and positions of children resources structure.