In a current project we are working on, we are using Spring ACLs as part of our authorization system. Basically each object in the system should have an ACL assigned to it,