1) Please add whitelisting.
2) Add any changes made to cloud to push changes to the devices (or sets a bit to pull changes that devices check on a tight time period or access timeout).
3) The above could be combined with login to set a new users (or switched users) security settings. Or regardless please load a users settings at login or user switch.