How should we control access to user data?

strategy (43), eng-strategy-book (32)