The ARPA2 sub-project libacl has a useful implementation for in- and ex-clusion, which can be used to express the rules for attributes. Use it.