We provide simple role based ACL mechanism (toggleable from CLI/GUI) https://docs.xgenecloud.com/en/v0.5/rest-apis/rest-acl
However, this simple ACL is not intended to encompass all business rules or hierarchies of every application. Hence we decided to provide each router (or controller) with its own middleware handler where these rules can be coded easily.
Explained in below diagram : https://docs.xgenecloud.com/en/v0.5/rest-apis/rest-acl#workf...