1. a user can own an entity/row/unit/whatever. They have full control over this unit.
2. a user can share ownership with another user/role.
3. a user can share various "rights" over any units they own -- CRUD, for example -- for any user/role.
4. a user can only interact with any unit they have a right to.
This can be implemented through a simple db table (or inline in the data itself) and doesn't depend on much. Once you build the middleware, you don't even need to think about the authorization layer.