The DELETE PROTECTION command deletes an access control list
entry (ACE) or the entire access control list (ACL) for a CDO
element or repository.
You need CONTROL access to delete protection.
The POSITION clause tells CDO the relative position of the ACE
to delete. ACEs are numbered starting with one. You can also
delete a particular element ACE by specifying the identifier or
identifiers contained in that ACE. If you omit the identifiers
and the POSITION clause, CDO deletes the entire ACL.
After the DELETE PROTECTION command executes, CDO resequences the
remaining ACEs in the ACL.
The default access type for all cases is ACCESS.