[ ] You must have a user-related data scheme. This means that different people can authenticate with your application, and the resources that are created must be assigned to individual users.
[ ] Customers must be able to delete their own data, and be prevented from deleting other customers' data.