1)Does Activiti BPM support user and group management for authorization? 2)Can the solution handle Tokens for authorization (e.g. SAML, Kerberos)? 3)Does it support XACML? 4)Does the solution support federation of authorization across security domains ?