Subject: Roles: RE: Comments on ebXML RegRep Security-002.doc (jdm)

> Lines 122-126:  This list of roles is inconsistent with the list presented

> in the box shown on Line 156 
I am still struggling with the roles required. You are right - they need to 
be the same 

Take a look at the Domain Spec.  The actor generalization diagram shows
users based on added responsibility (in essense priviledges).  They are
allow certain priviledges based on CRUD and access to object methods.  They
are NOT roles, but perhaps they could be recast.  I believe roles could be
determined by looking at the "valid" combinations of CRUD/Method access.


