a named grouping of information resource access permissions, defined for an application
                                                     
                        
                                                
                        
                        
                            an application-specific, logical grouping of users classified by common traits
                                                            
                                                     
                        
                                                
                        
                        
                            a semantic grouping of method permissions
                                                            
                                                     
                        
                                                
                        
                        
                            a semantic grouping of permissions for a given type of application user that allows that user to successfully use the application
                                                            
                                                     
                        
                                                
                        
                        
                            a way to assemble users with similar resource access permissions for an application by categorizing them into named collections