...
There is a convenience abstract class for those implementing policy enforcement points that need to be aware of access roles. If you subclass this Extending AbstractRolesAuthorizationDelegate class , then your implementation can be reduced to can mean having to write only a single method.