Authorization Scattering

Kind: anti-pattern

Layer: Enforcement Core

Record: architecture:authorization-scattering

Severity: discouraged

Scope: security_governance, model_governance

Formed by: Spread authorization checks across controllers, services, repositories, UI, and ad hoc conditionals without a central policy model.

Canonical: Ontology

A defect in which authorization checks are spread across layers with no central policy.

Listed in Architecture principles, after Security Theater and before Secret Sprawl.

Refactored by

Severity

Category

Force

Negated by

Linked from