Hi, This is really a nice concept and we are currently using the similar approach with Zermatt Claims based Identity framework. However; I see some some articles on .Net which says XACML is the best way of implementing Authorization; I don't have much experience in XACML; but could you provide some thoughts on this?