In EJBs, ACL checking is done using the Roles. Roles are an abstraction
of an application specific Logical Principals. These Principals do not
have any properties of Principals within a Security Domain (or Realm).
They merely serve as abstraction to application specific entities.