Very nice. I know how difficult it is to try to explain this stuff. I imagine that took a whole lot of work.
I have just a few minor suggestions:
Policy Templates: List of permissions that will appear in the Access Policy
Permissions: Keys whose value determines if a certain action can be performed or not
Change "(higher roles)" to "(roles with higher authority numbers)."
Change "one role per UG" to "one role per user per UG." ?
Maybe expand the brown section at the bottom a little. Something like this:
Resource Group: Resource Group Access ACL entries determine what users can do with resource in the group and whether they can see them or not.
Element Category: Like Resource Group Access but applies to elements (e.g., snippets, chunks, plugins, etc.) in a specific category.
Contexts: The mgr context ACL entries determine what users can do and see in general in the Manager. The web context is the default front-end context, so web Context ACL entries determine what actions the user can perform in the front end with resources in that context. You can create other contexts (usually front-end contexts) with their own ACL entries that determine what users can do with resources in that context.
Note: Even though the web context usually refers to the front end, users in the Manager need a Context Access ACL entry with a context of web in order to see web resources in the tree. They also need a Context Access ACL entry with a context of mgr in order to log in to the Manager.
You might also want to mention under User Group:
(Go to Security->Access Controls->User Groups tab, right-click on a user group and select "Update User Group.")
That place is really hard to find for new users.
Another thought is to put a little orientation at the top along the lines of:
In MODX Revolution, security restrictions are created by assigning users to User Groups and specifying what users in each group can do and see in the Manager and in the front end of the site. Based on the user’s role in the User Group, the user will be assigned a policy, which is a collection of specific permissions that determine what actions the user can perform in a specific context, with resources in a specific resource group, or with elements in a specific category.
It’s your page, so feel free to edit or ignore any of my suggestions. As is, it’s a fantastic resource for the visually inclined