I'm still thinking about how to approach this. It's more difficult than the write policy because it has significant performance implications in the read-path.
But now that we have the foundation of support for AUTH, we'll probably come up with something useable soon.
What is your use-case? Restric...