I would like to specify rules to control who, what and where actions can be elevated to run with admin privileges