Thanks for your reply, but, it is not clear mentioned, the actual question is, when there is a requirement to access a resource type servlet by any anonymous user of the website based on some CTA, there is no concept of permissions to that user, in that case how ACLs work?