AFS access control lists, or ACLs. There are two aspects of protecting files: who has access to the files, and who can change the access rights to the files. Some things to remember about AFS ACLs:
system:anyuser on the same ACL; all the user needs to do is issue the unlog command to receive the denied rights. Likewise for the network-address based groups listed below.
system:anyuser is any user of AFS, anywhere on the Internet
system:authuser is any user authenticated (with a token) in our AFS cell (cs.wisc.edu)
net:cs is any computer on the Computer Sciences Department networks
net:inst is any computer on the Computer Sciences Department instructional networks
net:stat is any computer on the Statistics Department network
net:wisc is any computer on the University of Wisconsin - Madison campus networks
host:www is the web server