Policy Administration Point
A Policy Administration Point, or PAP, is the component used to define, manage, and publish authorization policies.
- Acronym
- PAP
- Synonym
- PAP
Definition
A Policy Administration Point is the policy management component of an authorization architecture. It is where authorized actors create, edit, organize, test, validate, and publish policies, attribute models, and related configuration elements used later by the runtime decision engine. In practice, it is the policy management layer of a policy-based authorization model.
Why it matters
The PAP is where policy governance happens; its security and usability directly affect the quality and safety of authorization rules.
The Ariovis perspective
Authorization policies should be separated from application code when consistency, auditability or scale require it. Enforcement remains close to the resource while the decision is governed independently.
Related services
Common pitfalls
- Implementing a PAP without proper access controls can allow unauthorized modification of critical authorization policies.
Standards and protocols
- ISO/IEC 24762
- XACML
Explore this category
These concepts matter most inside a real project.
The first conversation helps establish your context, the systems involved and the next useful decision.