We already hand out scopes based on the user's access control
this will be our authorization layer for oauth and non-oauth tokens.