Access Control List
The Access Control List (ACL) defines the privileges (permission access rights) that particular principals have for a particular resource.
For more information about principals, see Principal Types.
For more information about ACL permissions, see Predefined Permission Access Rights.
Each ACL consists of access control entries (ACE). Each ACE controls or monitor access to an object. The ACE objects contain information about a certain principal and its permissions to access given resource.

The ACL contains a user assignment component, so you can manage the principals access rights for selected object instance.
For more information about managing ACL at runtime, see Managing Access Control List.