Yes, the pattern you listed above is similar to the one I used except that I call a load method from meta-data section of XHTML.
I have been working with Seam Security 3.1 and I have not seen anything for object level permissions. Hopefully with Deltaspike getting released this year security will be polished and most use cases covered. Thanks for your help!
Do you play Magic?
Get TopDecked MTG, the #1 Magic App, built by players, for players. Free to use, forever.