•Protect the
user's channels to agents
that manipulate
authority on the user's behalf
•Enable the
user to express safe security policies
in terms that fit the
user's task
•Draw
distinctions among objects and actions
along boundaries
relevant to the task
•Present
objects and actions using distinguishable,
truthful
appearances
•Indicate
clearly the consequences of decisions
that the user is
expected to make