Systems and methods are described in which the burden of implementing
access control policies, such that a computer user can access a restricted service under the control of the
access control policies of an access-restricted
system, is largely placed on the requesting user. More particularly, as part of a request user's request to access to a restricted service under the management of an access-restricted
system, the requesting user, on the user's computing device, instantiates an access request object of a strongly-typed dependent access request type, where the access request type embodies one or more
access control policies necessary to be permitted access. This transfers the burden of user validation to the user's computing device, leaving the access-restricted
system to quickly determine the validity of a received access request object to determine whether to reject the request or process the access request.