      Once you've been authenticated, Zope determines whether or not you
      have access to the protected resource. This process involves two
      intermediary layers between you and the protected resource,
      *roles* and *permissions*. Users have roles which describe what
      they can do such as "Author", "Manager", and "Editor". Zope
      objects have permissions which describe what can be done with them
      such as "View", "Delete objects", and "Manage properties".

        % Anonymous User - Sep. 22, 2002 1:22 pm:
         Roles classify users? How many roles can a single user have? At any one time?
         Permissions classify object access (attribute read/write+method calls)? Right?