Authorization

Authorization is the process of determining which resources an authenticated user may access. While authentication verifies the identity of the user, authorization decides on their permissions within a system.

Common models are role-based access control (RBAC), in which permissions are bundled and assigned via roles, and attribute-based access control (ABAC), which derives access decisions from properties of the user, the resource and the context. The guiding principle is least privilege: every user receives only the rights actually needed for the respective task – permanently excessive permissions are among the most common avoidable security risks.

Cleanly defined authorization also facilitates compliance evidence, because every permission is traceably justified and can be verified. Applied consistently in a context-dependent manner, authorization is a core mechanism of Zero Trust: access is decided for each individual request, not granted by default.