Even after an Actor’s Identity has been verified through Authentication, this does not mean that the Actor is free to perform any Action. The next step is Authorization.

Authorization uses multiple Attributes associated with an authenticated Entity to define the Scope of authority available to that Entity. The relevant Attributes are not fixed. Depending on the Context, System, and applicable Policy, they may include Country / Region, Organization, Project, Role, Qualification, Age / Status, License, Membership, Account Type, and other information.

Importantly, Authorization does not make the final “allow / deny” determination for an individual Execution Request. Rather, it establishes the Authorized Scope within which an Actor may have authority to act, based on the relevant target, Action, and conditions.

For Data, for example, Read, Write / Edit, and Export may fall within the Authorized Scope while Delete does not. For Systems, View, Configure, and Execute may be included without granting Admin privileges. Similarly, Search, Analyze, and Generate may be within Scope for APIs or Tools while Payment is excluded, and access may extend to Project A or Dataset B while excluding Confidential Data or External Resources.

An Action beyond this Scope is Out of Scope. Even when Identity has been correctly authenticated, an Actor has no authority to perform an Action that falls outside its Authorized Scope.

At the same time, being within the Authorized Scope does not mean that Execution is automatically authorized. A specific Execution Request may still require a Decision based on Fact, Evaluation, Policy, Authority, Context, and other Governance information. Where information is insufficient or uncertainty remains, additional Evaluation or Human Review may be required.

The distinction from Authentication is therefore clear:

Authentication answers “Who are you?” while Authorization defines the scope of “What are you authorized to do?”

The Authorized Scope established through Authorization becomes one element of Governance information referenced in subsequent Decision-making.

Accordingly:

In Scope ≠ Execution Authorized

Authorization defines the available scope of authority; Decision determines how a specific Execution Request should be handled within its Governance Context.