The apparatus has: a part that receives the personal certificate; a part that extracts a predetermined element in a hierarchy of a subject name included in the received personal certificate; and a part that decides an access right based on an organization to which a holder of the personal certificate belongs and an attribute other than a personal ID represented by a value of the predetermined elem