1 2 3 4 5 6 7 8 9 10 11
[request_definition] r = subject, resource, action [policy_definition] p = subject, resource, action [policy_effect] e = some(where (p.eft == allow)) [matchers] m = (p.subject == "*" || r.subject == p.subject) && r.resource == p.resource && r.action == p.action