Yes, but only very coarsly granular things.
- Permissions only work with entities. There are about ten different kinds of objects besides entities, that would also benefit a lot from being part of a uniform permission system.
- Permissions can only be defined for groups, not users, which is quite annoying if you want granular permissions
- With permissions only acting on groups, it also isn't possible to base permissions on user attributes. So you ultimately always have to model a permission set as a group, and then essentially have to have a synchronization mechanism that ensures that the right people are in the right groups
- This also makes scoped integration access impossible. You can't grant a third party app access to e.g. only your energy sensor data.