There should be predefined set of roles with privileges. They should be freely modifiable (including adding new one)