We propose two extensions to the SQL grant/revoke security model. In SQL, grants are unconditional, so the grantor must simply trust the recipient's discretion. We allow a grantor to impose limitations on how the received privilege may be used. Second, we provide a new means of selectively reactivating permissions that have been revoked. Although our examples are from DBMSs, the results (other than the treatment of views) apply to arbitrary sets of privileges, and to systems without a query language.