Entity aggregation for security computing resources involves an aggregation covenant that conditionally conveys rights to aggregation members. The ruling covenant is defined for protecting one or more computing resources by overriding system-level and/or entity-specific rights (e.g., super-users). An aggregation configuration module defines an aggregation-specific instance of an entity (user/device, process, or data) that receives the conveyed rights. The entity can use the rights conveyed only through its corresponding instance.