Deny-unless-granted permission model
User entity and authentication
Understanding the deny-unless-granted permission model