# checkmk_windows_acl Normalizes access on AIM-managed persistent Windows Checkmk files without recursively changing Checkmk directories or unknown/operator files. The role enables parent ACL inheritance and guarantees locale-independent well-known principals by SID: - SYSTEM (`S-1-5-18`): FullControl - local Administrators (`S-1-5-32-544`): FullControl - ALL APPLICATION PACKAGES (`S-1-15-2-1`): ReadAndExecute - ALL RESTRICTED APPLICATION PACKAGES (`S-1-15-2-2`): ReadAndExecute AIM does not add customer-specific administrator/user ACEs. Existing intentional parent or explicit ACEs are not blindly purged. Pass persistent AIM-owned file paths through `checkmk_windows_acl_paths`.