Yes, we keep them empty intentionally. This is to avoid any extra permissions being accidentally granted for users. For example, if a client uses location based security and we set the Geography field to /geography, it will give access to all geography or organization