MokoSuite uses a three-layer ACL system: User Groups define who the user is, Viewing Access Levels control what they can see, and Permissions determine what actions they can perform. Permissions cascade from Global Configuration → Component → Category → Individual Item, with settings at lower levels overriding those above. Groups form a hierarchy where child groups inherit parent permissions.

User Groups define the user’s role — Registered, Author, Editor, Publisher, Manager, Administrator, Super User. Groups form a hierarchy; child groups inherit parent permissions.

Viewing Access Levels are named sets of groups. Assign an access level to any article, category, module, or menu item to restrict its visibility. Default levels are Public, Guest, Registered, and Special.

Permissions control actions (create, edit, delete, publish) and cascade from Global Configuration → Component → Category → Individual Item. A permission set at the item level overrides everything above it.