Access control in multi-user interfaces

It's kind of related to the working group goals, hence I decided to simply ask the list:

Are you aware of any notable work regarding access control in multi-user interfaces?

I am currently trying to figure out how security models fit into the picture. For instance how authorisation concepts can be related to the abstract interfaces models we are currently working on.

