I\'m trying to setup an access control system to access an API I have developed. The resources are organized in the following hierarchy and the API foll