Pretty good. Some refinements: All passwords are enablers, so #1 enables viewing of the entire gallery. #2 enables viewing of just the album (and subalbums) on which it is applied. The `user` is not required (may be blank) but the login must match.
#3: There are many "rights" that can be assigned to an admin user.
a. User admin rights: This is kind of a master priviledge. A user with these rights can do anything. (No matter what the other rights might say!)
b. Options rights: Allows the user to make changes on the options tabs. (All users may modify their login credentials.)
c. Themes rights: allows the admin to view/make themes related changes. These are limited to the albums checked in his managed albums list.
d. Edit rights: allows the user to view/make edit tab changes to the albums checked in his managed albums list.
e. Comment rights: allows the user to make comments tab changes to the albums checked in his managed albums list.
f: Upload rights: allows the user to upload to the albums checked in his managed albums list.
g. View all albums rights: allows the user to view all albums. Without this right, the user can view only public albums and those albums checked in his managed albums list.
h. Overview rights: allows the user to view the admin overview page.
(#g and #h are post 1.1.7 release.)
4) Search guest user (edit>Gallery Configuration) is the name and password which allows viewing of the results of a search.
logins and right are inherited. So if someone has the rights to upload (view, etc.) an album he may do the same with that albums subalbums.
There is a plugin (user_logout) which will allow a theme to place a logout link (or if no one is logged in a login form) on a theme page. This is the same form that is displayed when the album/gallery/search page is password protected with a guest password.