Abstract: A method in a computer system for displaying allowed-to-authenticate information, the method comprising: receiving a selection of a security object; retrieving allowed-to-authenticate information for the selected security object, the information identifying an entity, a resource, and an action wherein when the entity attempts to authenticate to the resource the action indicates whether to allow or deny the attempt to authenticate to the resource; and displaying an indication of the selected security object along with the retrieved allowed-to-authenticate information.