Thanks, but again, within the application I have no problem constraining queries as needed. This is a higher level security issue. It is always possible for any user to intercept the transmission to the server, change it, and forward it on. This enables a user to escape from the provided logic and perform queries while remaining within the scope of the AwareIM application.
Example: Investigator logs in. Within the app, he/she will only ever see candidates within their own account. But using some very basic intercept techniques, they can intercept a query. The query could be:
FIND Candidate WHERE Candidate.Organization.ID=LoggedInInvestigator.Organization.ID
They intercept it and change it to:
FIND Candidate
Now they get all candidates. This is where protection rules are needed the most. The application logic works find, but a slightly sophisticated user can get past it. If the object is READ PROTECTED, then they won't see it using this technique.