How is the SID of the calling EXE checked?

Calling RProcess::SecureId() returns the SID of a process. When doing interprocess communication (IPC), the TSecurityPolicy class can be used to specify a security policy consisting of both capability and SID checks.