One thing we've considered WRT defaults is having a single user:* (or organization#member, depending on scope) kind of relation for a given role (rather than having to write a relation for every user as they register, etc), and then have a relation for the "removed" set of users that is excluded from the permission. I'm not sure how this would perform though, in comparison. Curious what others think about that.