We have done a splendid job of butchering up ACL across our install with the express intent of making phabricator as frustrating as possible for all of our users. There are well defined rules across many applications for who can and cannot perform specific actions, including some custom applications, whose capabilities are themselves sometimes editable by specific groups of users.
We'd like even more insight into these machinations, and a good place to start would be allowing us to see which users have edited application policies so that we can punish them if they do it incorrectly.