ACLs allow per-user permissions: which commands they can run (+get -set), which keys they can access (~cache:*), and which channels (¬ifications). You can create read-only users, write-only users, and admin users without sharing a global password. Managed via ACL SETUSER or aclfile.