The most popular classic design rights organizations of small sites, authority Table 5
Considering the plethora of users, if users add a privilege is very cumbersome
In this case the user could be given to the packet, a user in a group, a group of users may have multiple roles, a single user can have their own special character, and therefore. A user all the roles: user roles + user group owned by role
If the permission finer granularity of points, you need to give permission to the functional classification