Based on the security methods (attributes, permissions, etc.), describe in detail the process you would use to allowing an individual that is using a client to view the documents (including the acceptable use policy they signed employee orientation), but not change or delete?