We check for tokens and registries - but we should also validate that their scope / privileges suffice.