I feel some systems already operate like this, but typically it was done for fraud and abuse, now it will be done for permissions as well.