@mariusor The local copy should be enough if you check the signature (Mitra signs POST requests and adds integrity proofs to activities).
Yes, I am very interested in learning about your approach to ACLs. I tried to implement proper access control in a little side project, and that turned out to be more complicated than I expected.