The DELETE PROTECTION command deletes an access control list entry (ACE) or the entire access control list (ACL) for a CDO element or repository. You need CONTROL access to delete protection. The POSITION clause tells CDO the relative position of the ACE to delete. ACEs are numbered starting with one. You can also delete a particular element ACE by specifying the identifier or identifiers contained in that ACE. If you omit the identifiers and the POSITION clause, CDO deletes the entire ACL. After the DELETE PROTECTION command executes, CDO resequences the remaining ACEs in the ACL. The default access type for all cases is ACCESS.