A system and method for authorization to adaptively control access to a
resource, comprising the steps of providing for the mapping of a
principal to at least one role, wherein the at least one role is
hierarchically related to the resource; providing for the evaluation of a
policy based on the at least one role; and providing for the
determination of whether to grant the principal access to the resource
based on the evaluation of the policy.