# ACL: how to restrict access to a defined list of people?

**URL:** <https://forum.solidproject.org/t/acl-how-to-restrict-access-to-a-defined-list-of-people/5176>\
**Category:** General Discussion\
**Created:** [March 24, 2022, 11:25am UTC](https://forum.solidproject.org/t/acl-how-to-restrict-access-to-a-defined-list-of-people/5176 "2022-03-24T11:25:11Z")\
**Posts on this page:** 2\
**Page:** 1

<div class="post-metadata">

**Author:** ![joe](https://dub1.discourse-cdn.com/flex017/user_avatar/forum.solidproject.org/joe/32/2916_2.png) [@joe](https://forum.solidproject.org/u/joe)\
**Post date:** [March 24, 2022, 11:25am UTC](https://forum.solidproject.org/t/acl-how-to-restrict-access-to-a-defined-list-of-people/5176/1 "2022-03-24T11:25:12Z")

</div>

Hello,

Let’s say that my organization contains different groups of users. Let’s say “Staff” and “Students”

How can I make resources hosted on Staff member pods only accessible to Staff members? How and where can I define who is part of the Staff group? And make sure that no student can pretend to be a Staff member?

Also, would it be possible ( and would it make sense ) to store data on _Student_’s Pod, only accessible for Staff members? Or should Pod owners always have full control over their data?

---

<div class="post-metadata">

**Author:** ![bourgeoa](https://dub1.discourse-cdn.com/flex017/user_avatar/forum.solidproject.org/bourgeoa/32/291_2.png) [@bourgeoa](https://forum.solidproject.org/u/bourgeoa)\
**Post date:** [March 24, 2022, 5:33pm UTC](https://forum.solidproject.org/t/acl-how-to-restrict-access-to-a-defined-list-of-people/5176/2 "2022-03-24T17:33:33Z")

</div>

1. To restrict access to staff you should use acl:agentGroup predicate ([Web Access Control](https://solid.github.io/web-access-control-spec/#acl-agentgroup))

2. Actually a pod-owner has full control on ACL of the pod  
You may consider that the pod-owner in not the pod-WebID but an other admin. In this case the Student’s pod can have areas of datas that the student’s WebID cannot have Control on. The consequence is that the Student’s pod is not fully owned by the Student and an admin can have access to the private students datas.  
The solid spirit is somehow broken. It is better to give access to the student on a dedicated staff managed content
