TernFS itself is currently totally permissionless. We could add some basic access control data to the directory policies.
This does not need to be enforced by the kmod (but maybe one day it could be), however it would be useful for other clients (e.g. S3 proxies) in order to keep access controls consistent. This should be group based, so each directory would have a list of groups that are allowed access.