It would be nice to have more information on Trusted Subsystem as I have plenty of back-end data that needs to be exposed in a read-only format. I also see mentioned here multiple times about SSO, however from other sources I understand that SSO is not entirely needed if Trusted Subsystem is the authentication method used.