Each user is given appropriate access rights (or privileges) on specific database objects.
•Users can obtain certain privileges when they create an object, and can pass some or all of these privileges to other users at their discretion.
•Drawback of this policy
oAn unauthorized user can trick an authorized user into disclosing sensitive data.