GCC implemented a project-centric security model for their ADF applications to enable their construction sites to securely access centralized systems. Users are authenticated using Oracle Single Sign-On and assigned roles and privileges at the project and module level by security managers. These privileges are checked using EL expressions to control UI rendering on a per-page and component level. The infrastructure was set up using WebLogic, HTTP Server, and Identity Management integrated with the ADF applications. Reusable task flows, libraries, and templates help manage the growing portfolio of ADF applications.