val superuser : tThe superuser role has all privileges
val of_domain : int -> tThe role associated with a specific domain id
restrict role domid returns a new role which contains the subset of role which applies to domain domid
type permission = val check : t -> permission -> Xs_protocol.ACL.t -> unitcheck role permission acl throws Permission_denied if role does not have permission according to the access control list acl
val has : t -> permission -> unithas role permission throws Permission_denied if role does not have permission