THE SHORT ANSWER

Authentication establishes who or what is requesting access. Authorization decides what that identity may do. Roles group responsibilities; permissions allow specific actions. Least privilege limits access to the minimum necessary scope and duration.

Authentication is identity; authorization is permission

Identity and permission questions
QuestionControl
Who are you?Authentication
What may you read, change, send or delete?Authorization
Which job responsibilities apply?Role
How much and how long?Scope and duration

Access changes with work

  • Use named identities instead of shared accounts.
  • Separate admin and ordinary access.
  • Expire temporary access.
  • Review high-impact permissions.
  • Remove access during offboarding.
  • Include service accounts, API tokens and vendor integrations.

Fail closed where consequence is high

New users or integrations should not inherit broad access by convenience. Exceptions should be explicit, time-bound and reviewable.

Turn guidance into an owned business action

Choose one relevant account, system, data set or workflow. Record the owner, current control, most important failure, detection signal, response step and recovery dependency. Escalate specialist, legal or regulatory questions to qualified advisers for the applicable context.

Sources & further reading

  1. Authorization Cheat Sheet

    OWASP Foundation. Security guidance emphasizing least privilege, deny-by-default behavior and authorization checks on every request. Implementation details depend on the application's threat model.

Examples and exercises are illustrative unless attributed to a source. No independent expert review is claimed.

A correction, a counterexample or an experience worth sharing?

Join the conversation ↗