The resource web

A resource embodies the authority to perform an operation on a database. The operation may be anything expressible in SQL. Access control is achieved by constructing a resource web that simultaneously defines and enforces the access policy.

The accountant access control policy

The above resource web diagram expresses an access control policy. A user with access to an <Accountant> resource can access both the price list resource and the weekly sales resource. A user with access to the price list cannot access the weekly sales or <Accountant> resources.

