The document analyzes the use of 'feature' as a modeling entity for access control policies (ACPs) in software development, emphasizing the need for incorporating ACPs early in the design process. It discusses two primary approaches—meta-model based and pattern based—highlighting their advantages and limitations in representing dynamic and complex ACPs. The paper concludes with insights into further research directions for improving the modeling of ACPs within organizational security frameworks.