Аннотация:In this paper safety problems for a simplified version of entity-based access control model are considered. By safety we mean the impossibility for a user to acquire access a given object by performing a sequence of legitimate operations over the database. Our model considers the database as a labelled graph. Object modification operations are guarded by FO-definable pre- and post-conditions. We show undecidability of the safety problem in general and describe an algorithm for deciding safety for a restricted class of access control policies.