What's the consistency model for operations against your API? When my backend grants a user access to some resource, will all subsequent permission checks immediately grant that access?
If not, how are user signups supposed to work? If I create a user and set up their permissions in Warrant, will my users' first-time experience consist of a permission denied error?