package AD.DELETE
default allow := false
allow {
input.owner == input.requester
}
input.role == "admin"