The security token is a thing granted to users which has a series of bits which specify which privileges" you get in the OS. it is kind of like a capabilities system (see wikipedia), but does not have the sophisticated revocation system of experimental capabilities OSes.