This paper describes the design and development of a flexible domain-based access control infrastructure for distributed Collaborative Environments. The paper proposes extensions to classical RBAC models to address typical problems and tasks in the distributed hierarchical resource organisation that came from the practical experience in developing industry oriented virtual laboratories infrastructure. The proposed extensions/solutions address the following problems: hierarchical resources policy administration, user roles/attributes management, dynamic security context and authorisation session management, and others. The paper provides implementation details on the use of XACML for fine-grained access control policy definition for domain based resources and roles organisation. Special attention is given to practical implementation of the authorisation session management as a key component of the distributed hierarchical access control infrastructure. The paper analyses the required f...