EN - FR - DE - ES - IT - PT -

LexiconDream

✅ Authorization

The process of granting or denying access to resources.

Authorization

Authorization decides what an authenticated user can do. Authentication opens the door. Authorization determines which rooms you can enter. A help desk employee logs in successfully, but that does not mean she can read the CEO's email or modify payroll records. Authorization checks her permissions before every request and denies anything outside her role.

The common models are role-based and attribute-based. Role-based access control groups permissions by job function. Every accountant gets the same set of rights. It is simple and auditable, but it can be coarse. Attribute-based access control evaluates policies against many factors: department, clearance level, time of day, and the sensitivity of the resource. A contractor can access project files during business hours from a managed device, but not from a personal laptop at midnight. The trade-off is complexity. Attribute policies are harder to write and maintain. Most organizations start with roles and add attributes where the risk justifies it. The principle is the same either way: deny by default, grant only what is needed, and review grants regularly.

Authorization best practices

Authorization failures are quiet. Nobody notices the extra permission until someone abuses it or an auditor finds it.

Comments

No comments yet. Be the first to share a thought.

Leave a comment