package AD.READ
default allow := false
allow {
input.userUuid == input.owner
}
input.role == "admin"