Alex Edwards suggests to renew the token after a privilege change e.g. the token must be changed when the user logs in and out