If there were such a permission scheme, such as in Facebook's now likely defunct cryptocurrency idea, you would not need proof of work. You'd just have a list of authorized signers of new blocks and if someone does something bad you kick them off the list. This is basically how the web PKI system works with browser certificate whitelists.
Lots of cryptocurrency critics over-argue their case by denying that this was a novel innovation, but yes it was novel. It has big downsides but it works. Personally my big issue with crypto other than the energy waste is that the cryptocurrency ecosystem itself is toxic and full of scams and other trash.