Library / Users & access / Authorization
No. 054·noun·also called access control, AuthZ, permissions check

Authorization

How an app decides what a signed-in person is allowed to see and do.

SPECIMEN · DIAGRAM · COMPARE
Who are you?

Authentication

  • Sign in with a code
  • Happens once per session
What can you do?

Authorization

  • Checked on every action
  • Enforced on the backend
Definition

What it is

Authorization answers "is this person allowed to do this?" A viewer can read reports but not edit them; only the owner can delete a project; only admins can see billing.

It must be enforced on the backend. Hiding a button is a courtesy, not security: anyone determined can call the backend directly.

When you describe it, list the actions and who can do each. A simple table of roles against actions is the clearest way.

Say it like a builder

How to ask for it

Vague

“Make sure people can't mess with each other's stuff.”

Precise

“Add authorization rules, enforced in the backend: users can only view and edit their own invoices; admins can view all invoices but not edit them; only the account owner can delete. Return a clear "not allowed" error otherwise.”

Why it works

"Can't mess with" is fuzzy; authorization rules listed per action and enforced on the backend are testable.

In the wild

You've seen this in

  • GView-only vs edit access on a Google Doc
  • SAdmin-only billing pages in Slack
  • OOnly the author can edit a GitHub comment
Usage note

Often confused with