I was thinking more in terms of a user being a domain object and how 
you'd deal with adding/finding/removing users in a generic 
authentication plugin in a persistence neutral manner that wouldn't need 
rewritten once a final persistence mechanism was chosen.  It would not 
be done the same way in Glorp as in Gemstone for example.  Perhaps it'd 
be more of a mini-framework where you'd have to subclass a few things 
and fill in a few blanks before things worked.

