I just told PI to generate itself a permissioned_* equivalents of read,write,bash,edit. Now, permissioned_read,permissioned_write,permissioned_edit have full access to anything from current dir and deeper, and permissioned_bash is always permission-gated.
Default read,edit,write,bash are disabled.
It seems to work really good.
Generally, I'm in awe. I think I've already changed the way I work.