Does anyone with a permanent authentication token have full read and write access to all entities in the database, even if permissions do not allow anyone to read or write? I guess I'm wondering how the owner of a permanent authentication token fits into permissions