The security process that determines what actions an authenticated principal is permitted to perform on specific resources within a system. Authorization evaluates the subject’s identity, role, attributes, and contextual factors against a policy to produce an access decision, operating as a distinct layer from authentication and separate from audit.

Content

  • The conceptual separation of authentication from authorisation was formalised in early multi-user operating systems of the 1960s and 1970s, where distinct mechanisms controlled who could log in and what files they could access. Unix file-permission bits (owner/group/other read/write/execute) represented one of the first widely deployed discretionary access-control (DAC) models. The Trusted Computer System Evaluation Criteria (1985) introduced mandatory access-control (MAC) requirements for high-assurance systems, in which a central security policy overrode user discretion.
  • Modern authorisation models fall into several paradigms. Role-Based Access Control (RBAC), standardised by NIST in the 1990s and formalised as ANSI INCITS 359-2004, assigns permissions to roles rather than individuals, simplifying administration at scale. Attribute-Based Access Control (ABAC) evaluates arbitrary subject, resource, and environmental attributes against fine-grained policies expressed in XACML or OPA (Open Policy Agent) Rego. Relationship-Based Access Control (ReBAC), popularised by Google’s Zanzibar paper (2019), derives permissions from object-relationship graphs, enabling scalable fine-grained sharing. OAuth 2.0 and OpenID Connect provide delegation and federation for distributed web and API ecosystems.
  • Authorisation infrastructure in enterprise environments includes centralised Policy Decision Point services (OPA, AWS Verified Access, Azure AD Conditional Access), privilege access management (PAM) platforms for just-in-time elevated access, and API gateways enforcing token-scoped permissions. Microservices architectures introduce service-to-service authorisation challenges addressed by service meshes with mTLS and sidecar policy enforcement. Identity governance and administration (IGA) platforms manage the lifecycle of authorisation entitlements, detecting and remediating excessive or conflicting privileges.
  • In 2024–2025, authorisation is evolving to accommodate AI agents acting on behalf of users, requiring capability-scoped tokens that constrain the blast radius of compromised or misbehaving agents. Zero Trust principles mandate continuous authorisation re-evaluation based on real-time risk signals (device posture, anomalous behaviour) rather than session-level grants. Regulatory frameworks increasingly require fine-grained authorisation controls over personal data processing, and data-mesh architectures are driving domain-oriented policy management to keep authorisation close to the data it governs.