YOU GENERATE THE PERMISSION ON AN API AND BRING IT IN TO THE KONTENT SO THAT IT CAN BE TRANSFORMED INTO A JSON STRING THAT IS HELD IN A DATABASE SO IT CAN BE REFERENCED BY AN AUTHORIZATION SERVICE THAT PARSES THE JSON STRING AND COMPARES IT TO A POCO THAT IS GENERATED BY A JSON STRING THAT IS PASSES IN THE AUTHORIZATION REQUEST. WE WILL CACHE THIS STRING JUST TO BE SURE WE'RE NOT HITTING THE API TOO MUCH. RIGHT NOW WE DON'T HAVE THE API SO JUST HARDCODE THE VALUES WE KNOW AND IT WILL GET FIXED LATER