@yetitwo these are not roles
there are documents protected by acls and there are permissions through group membership, but this is a different thing.
The case described above is the permissions granted because the user is a "special entity" for a document.
"If user is a C entity for a document protected by C's acl - then the user must have certain permissions on that document."
B - is a relationship: "special entity" - user - document
And in this case, I want to check if a particular user is a "special entity" for at least one document protected by a given ACL, with a certain permission granted because of it