Permissions are assigned per account, organization and resource type. The permission is either
read or write where write implies read.
There are some caveats. Currently, system administrator is the only account able to perform the following operations.
Organization user with full permissions can create new organization administrators. It is enough
with write permissions to the resource type perm in order to make a user organization
administrator. Since that implies that the user can add its own permissions. Hence, be careful what
permissions is given to which users.
Permissions can be revoked by a user that have write permissions to the perm resource.
See authorization examples for examples of permission handling.