<?xml version="1.0"?>
<policy 
  xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance"
  xsi:schemaLocation="http://www.trl.ibm.com/projects/xml/xacl xacl.xsd"
  xmlns="http://www.trl.ibm.com/projects/xml/xacl">
<!-- ===================================================
  1. Alice can read name fields.
 =================================================== -->
  <xacl>
    <object href="/personnel_info/name"/>
    <rule>
      <acl>
        <subject>
          <uid>Alice</uid>
        </subject>
        <action name="read" permission="grant"/>
      </acl>
    </rule>
  </xacl>
<!-- ===================================================
  2. Bob can read and write salary fields.
 =================================================== -->
  <xacl>
    <object href="/personnel_info/salary"/>
    <rule>
      <acl>
        <subject>
          <uid>Bob</uid>
        </subject>
        <action name="read" permission="grant"/>
        <action name="write" permission="grant"/>
      </acl>
    </rule>
  </xacl>
</policy>

