This paper tackles the problem of defining an appropriate access control model for multi-user systems providing adaptive resource reservations to unprivileged users. Security requirements that need to be met by the system are identified, and an access control model satisfying them is proposed that also does not degrade the flexibility available on such systems due to the adaptive reservations framework. Also, the implementation of the proposed model within the AQuoSA architecture for Linux is briefly discussed.