ACLs migrating from ix-applications to host path datasets

I’m using shell to ’ cp -r /ix-app/app /hostpath/app
I set up the datasets with the ‘apps’ default config, or least intended to.

I expected apps would then own everything. But everything is owned by root with apps user also having full permissions.

What is the intended/ideal ACL for hostpath apps in normal circumstances?