Deciding which actions an authenticated user is permitted to perform.
The process of granting and controlling an authenticated principal's operating permissions on a resource. Unlike authentication, which verifies identity, it differs in deciding "what this person is allowed to do."
© 2026 ITBGM