Simpler Structure Jari asks, “can’t we just define each RLS service by its resource list”? I don’t think so RLS service uses a lot of provisioned data Resource list is just one piece Spec also defines allowed packages Other things for the future Index to authorization policies Back end subscription policies Keep it extensible |