Review the security (permissions management) API in the client and build a new one on the new repository instance API _if necessary_.