Possible ideas: - Define some secure way of filtering the data that the list endpoint returns - Should be flexible and require minimal effort