In chapter 5.2. About Java Security Manager Policies there is "The security policy can define permissions based on the location of code or on the code's signature.", but it can be based on subject's principals too, it should be added.
Moving to ON_QA. The changes should be available for review on the documentation stage within an hour or so from this comment. http://documentation-devel.engineering.redhat.com/site/documentation/en-US/JBoss_Enterprise_Application_Platform/
Verfied on stage.