You call this an anti-pattern (and rightfully so, since cluttering application code like this is a nightmare), but then what is the better pattern? In an app with >100 entities and >500 types of business transactions, many of which can fail in unexpected ways, will I be forced to maintain what was changed in Permify and roll back manually?
If yes, then this is quite a burden and might be a valid reason for not using a separate permissions store. But maybe there are better ways...?