1. Cleanup of APIs, possibly drop APIA/APIM distinction
      1. For example, listing available DS is an APIM call but view them is an APIA. This leads to additional challenges in coding that are
      2. Combine the APIs or make a better distinction, so Manage and Access is a reasonable distinction, but needs to be rethought
    2. Tighter Integration of Security via FESL or an undefined security mechanism
      1. Queries only reporting objects you can see
      2. API operations returning things you have access to