A method for controlling access to information, which includes a plurality of
data
objects, on a computer system being accessible to a plurality of users is provided
which generally comprises providing an access right for each relationship between
a user and a data object, wherein each user can have a plurality of relationships
to each data object, determining each relationship between the user and the data
object when a user requests information about a data object, determining the security
classification for each relationship between the user and the data object, and
then granting the user access to the data object if one of the security classifications
for all the relationships is equal to or greater than the security classification
of the data object, and denying the user access to the data object if the security
classifications for all the relationships is less than the security classification
of the data object.