https://atproto.com/guides/permission-sets#permission-set-de...
https://atproto.com/guides/permission-sets#permission-set-de...
I believe what they are referring to is custom permissions set by the person logging in, regardless of what the app itself requested.
e.g. login, disable all writes, all attempted repo writes using that oauth token fail.
Today, apps can limit the permissions they request during login. I don't see the dynamic, assuming they mean something where during approval you can deselect options, as a horrible situation. That's something very few apps do even outside of atproto.
But all that aside i think a protocol aiming to liberate users and be an open app platform cannot be held to the same standards as corporate garbage that we don't expect to behave differently. Atproto needs to show some commitment to the values of putting users first, its so close.
I think the Bluesky domination and recent "funding" from Bain Capital move it away from these goals. I've left the app and ecosystem. "user" growth is negative and they are misleading about how many "accounts" there are.
The hero holds the lies: https://atproto.com/
To get to the widely cited 43M "users" you have to count DIDs (accounts, not users) and include takedown and deleted...