I'll be changing MemberData.setSecurityProfile to use user._doChangeUser() instead of hitting the attributes directly, if nobody sees a problem with that. Shall I also change this in 1.4 branch ? Florent -- Florent Guillaume, Nuxeo (Paris, France) CTO, Director of R&D +33 1 40 33 71 59 http://nuxeo.com fg at nuxeo.com