Groups, modules and permission should be mapped in db. for authorization use enums with Security annotation.