Basically, this means that a User is restricted not by their ’rights’, but by what Permissions the User has. It allows more fine-grained control of various actions from within an application.
They are done via ACLs, or Access Control Lists, which are basically just
Permissions. A Permission can be anything, such as ’content_types’, which allows access to the Content Types page. If the User doesn’t have that Permission (gained through their User Group in Revo), they wont have access to the Content Types page.