Authorization

Kind: mechanism

Layer: Security Core

Record: architecture:authorization

Severity: mandatory

Scope: API, domain action, data access

Canonical: Ontology

A mechanism that decides, from a policy, whether an authenticated principal may perform an action on a resource.

Listed in Architecture principles, after Authentication and before Access Control.

Requires

Reinforces

Enables

Conflicts with

In tension with

Tensions

Violated by

Refactored by

Severity

Category

Enabled by

Refactors

Linked from