Authorization
How an app decides what a signed-in person is allowed to see and do.
Authentication
- Sign in with a code
- Happens once per session
Authorization
- Checked on every action
- Enforced on the backend
What it is
Authorization answers "is this person allowed to do this?" A viewer can read reports but not edit them; only the owner can delete a project; only admins can see billing.
It must be enforced on the backend. Hiding a button is a courtesy, not security: anyone determined can call the backend directly.
When you describe it, list the actions and who can do each. A simple table of roles against actions is the clearest way.
How to ask for it
“Make sure people can't mess with each other's stuff.”
“Add authorization rules, enforced in the backend: users can only view and edit their own invoices; admins can view all invoices but not edit them; only the account owner can delete. Return a clear "not allowed" error otherwise.”
"Can't mess with" is fuzzy; authorization rules listed per action and enforced on the backend are testable.
You've seen this in
- GView-only vs edit access on a Google Doc
- SAdmin-only billing pages in Slack
- OOnly the author can edit a GitHub comment