Authorization defines which users or systems have access to specific resources. It complements authentication by ensuring that only authorized users can perform actions. This is crucial for security and data protection.
Use this profile to understand the building block briefly, place it in the model, and switch to the 360° assessment when needed.
Theoretical construct: explains a term, principle, or mental model.
What you need to understand to reason about a domain.
Authorization determines which actions an already identified subject may perform on a resource.
The approach grew from the security need to control access after an identity has been checked. NIST describes digital identity and access decisions; OWASP and OAuth 2.0 shape practical implementation, with no single originator established.
A request combines an identity, a resource, and an intended action. A policy evaluates that combination, an enforcement component allows or denies it, and an audit record keeps the decision traceable.
The person, service, or device whose permission is evaluated.
Rules state which actions are allowed under which conditions.
Technology applies the decision at every relevant access point.
Authorization is fundamental to APIs, applications, and internal services. Least privilege, separated roles, and traceable changes limit harm from misconfiguration or compromised identities.
Where this building block is located in the topic model.
Explore how this building block connects to concepts, methods, technologies, and tools.
These sources establish the term and its professional meaning.
All direct connections of the current building block in a compact text view.
This classification shows where the building block typically matters, how demanding it is, and what kind of impact it has in the model.
The level within the organization (enterprise, domain, team) at which the AssetBlock is applied.