Learning outcomes
- Normalize each request into subject, resource, action, context, and policy inputs.
- Separate route, object, and delegated authorization decisions.
- Apply default deny, least privilege, separation of duties, and bounded exceptions.
- Test, deploy, explain, observe, and retire policy.
Scenario
A finance application permits one employee group, requires a managed device for write operations, and allows a short emergency exception. Reviewers need to identify which rule granted each request and when the exception ends.
Ordered learning units
Access Control
Combine policy, reliable decision inputs, enforcement, and evidence to control actions on protected resources.
Separate three different access decisions
Trace authentication, gateway route authorization, and application permission as separate decisions with separate evidence.
Authorization Request
Model each decision with a subject, resource, action, context, policy, and evidence instead of a user role alone.
Default-Deny Authorization
Deny unmatched and indeterminate requests, then add explicit narrow grants with tested conflict and failure behavior.
Choose DAC, MAC, RBAC, or ABAC
Compare owner-controlled, centrally mandated, role-based, and attribute-based authorization for one resource.
Capability-Based Security
A capability is an unforgeable reference that carries authority to perform defined operations on a resource.
Object and Action Authorization
Authorize every application action against the exact object instead of trusting route access, a role, or an object ID.
Do not treat a scope as a resource permission
Separate OAuth scopes, roles, entitlements, consent, and application permissions before a resource server authorizes an action.
Place the components of a policy system
Place policy administration, information, decision, enforcement, distribution, and evidence components in one access system.
Distributed Security State
Control policy, identity, revocation, key, context, and quota state across replicas with explicit freshness and failure semantics.
Choose where authorization decisions and enforcement run
Compare central and local authorization while preserving complete enforcement, current context, and safe failure behavior.
Policy Combining and Conflict
Policy combining defines how allow, deny, not-applicable, indeterminate, inherited, and local results become one decision.
Test authorization policy as a decision system
Build deterministic authorization tests for allow, deny, boundaries, conflicts, failures, stale context, and bypass paths.
Operate temporary and break-glass access
Grant short-lived and emergency authority with explicit scope, expiry, approval, monitoring, revocation, and review.
Operate the authorization policy lifecycle
Move access policy from protection need through review, testing, staged deployment, observation, rollback, and retirement.
Authorization Decision Log
Record enough structured evidence to explain and test an access decision without storing credentials or excess personal data.
Evaluation questions
- Does each rule name the subject, resource, action, and required context?
- Do negative tests cover another tenant, object, action, route, and stale context?
- Can one production decision be connected to the effective reviewed policy and final application action?
Completion conditions
- Build and test a default-deny policy for one route and its object actions.
- Demonstrate review, staged deployment, explanation, emergency expiry, rollback, and decision evidence.
