Custom objects and folders
There is an important difference: custom objects and folders can only receive permissions from application security templates, since versioning security templates can only be applied to documents. The relationship between a custom object or folder and an application security template is done using a GUID assigned to the template. The GUID is called by the application whenever the program's logic requires the security state described by the template. Associations can only be made by customized applications created using a Content Cortex API.
The Administration Console for Content Platform Engine security policy wizard lets you create application security templates as part of defining a security policy. It can also automatically assign a GUID to the new template or use a 32-bit GUID that your own program generates.