There should be a way to explicitly add a resolver that gets the full auth context for a permission, as an escape hatch for custom functionality.