Translating each source system's native permission scheme into one common, filterable model.
Mapping tables per source-system permission type (POSIX ACL, RBAC scope, sensitivity label) to a common schema.
Standard ETL/mapping tooling