Define and document the types of accounts allowed and specifically prohibited for use within the system; Assign account managers; Require for group and role
We present a paradigm for access control to typed objects logically connected to form a hierarchy, whereby each object has a single parent, and may have children. Protection domains are divided into t