Similar to Linux permissions, a bitset will be generated for each request, containing a user's specific permissions to access that page. - [ ] Implemented in the API - [ ] Checked both in the frontend and in the API to prevent caching-based abuse