← All labs

Access check simulator

Step through a simplified DACL vs token decision — same rules as the real algorithm, fewer edge cases.

1. Token identity

2. DACL (simplified)

  • ALLOW AU Read, Execute
  • ALLOW BA Read, Write, Execute, Delete
  • DENY BU Write, Delete

3. Requested access

SRM decision (educational)

Granted: Read

Denied: Write

  1. Token: Standard user [BU, AU]
  2. Requested: Read, Write
  3. ALLOW Read — ACE matches AU
  4. DENY Write — ACE matches BU