Yes, this is what we do as a workaround. E.g. first we check if the requester has the permission to add a new member to a resource, then execute the change. It's a matter of miliseconds (ideally). But it's still not part of the same transaction, which is not perfect in my oppinion.