How should Diaspora API scopes be broken down?

We need a consensus of how the API scopes (permissions) should be broken down. Should we keep it simple (e.g, just read and write) or break it down further? Should we have the option to have applications ask for certain permissions and then allow users to disable some permissions that the application asked for on an application page? Please see as some opinions have already been spoken.

Note: This discussion was imported from Loomio. Click here to view the original discussion.