We have introduced a new hook hook_webform_access_rules() (and its counterpart hook_webform_access_rules_alter()) to let external modules leverage the access system of webform module.
Through the hook you can supply additional access rules that should be managed on per-webform level. Provide additional access rules into the webform access system and then website administrators can assign appropriate grants to your rules for each webform via admin UI (the "Access" tab of a webform). Whenever you need to check if a user has access to execute a certain operation you should do the following:
\Drupal::entityTypeManager()->getAccessControlHandler('webform_submission')->access($webform_submission, $my_rule_name, $account)
The return is either a positive or a negative result depending on what the website administrator has supplied in access settings for the webform in question.
Note, there are 2 "magical" suffixes in access rules machine name:
_any: means to grant access to all webform submissions independently of authorship_own: means to grant access only if the user requesting access is the author of the webform submission on which the operation is being requested.
That way you can define 2 access rules in this hook: do_operation_any and do_operation_own. Then, you can query just for do_operation access and both access rules will be checked for the user who is requesting the access.
Consult webform.api.php file for further technical details.