AccessControl
One of the following child elements can be used to attach an access control policy to matching requests:
Attaches a custom access control implementation provided by a plugin
Attaches an access control policy using the XML-based plugin provided with the SP. This is a short-hand for embedding the policy in the element above, if you want the policy inside the RequestMapper's configuration file anyway.
If no element is included (or inherited or implicitly enabled), any access control is left to the resource itself and the SP simply passes its session information along.
If an error occurs when processing this element, a dummy policy to deny access is installed to prevent accidental exposure.