Identity and Access Management glossary

Explore the concepts used across Identity and Access Management, Identity Governance, Access Management, privileged access, authorization and identity security.

Definitions are organized to support search and navigation between related concepts.

Search for a term

Browse by letter

Filter by category

Glossary terms

51 terms· Page 1 of 3
  • Authorization

    Access Control

    Access control is the broader security discipline that enforces authorization rules on access to resources, actions, and data.

  • Authorization

    Access Remediation

    Access Remediation is the process of correcting inappropriate, excessive, conflicting, or unjustified access.

  • Authorization

    Access Simulation

    Access Simulation is the evaluation of the effect of a proposed access change before it is actually granted.

  • Authorization

    API Gateway

    A control layer that secures and governs API traffic, especially for machine-to-machine access.

  • Authorization

    Application SoD

    Application SoD is the detection of toxic combinations of rights within a single application.

  • Authorization

    Attribute-Based Access Control

    Attribute-Based Access Control, or ABAC, is an authorization model that makes decisions based on attributes of the subject, resource, action, and environment.

    ABAC
  • Authorization

    Authorization

    Authorization is the process of determining what an authenticated subject is allowed to do on a given resource under specific conditions.

    AuthZ
  • Authorization

    Authorization Management

    Authorization Management is the IAM domain responsible for defining and enforcing what authenticated identities are allowed to do.

  • Authorization

    Authorization Management Platform

    An Authorization Management Platform, or AMP, is a platform approach used to manage fine-grained authorization across multiple systems and applications.

    AMP
  • Authorization

    Authorization Matrix

    An Authorization Matrix is a structured mapping of functions or actions against roles or user populations to show who may do what.

  • Authorization

    Authorization Policy

    An authorization policy is a formal rule set that defines the conditions under which access should be allowed, denied, constrained, or escalated.

  • Authorization

    Authorization Scope Dimension

    An Authorization Scope Dimension is a structured parameter used to define the perimeter within which an access right applies.

  • Authorization

    AuthZen

    AuthZen is a standards-oriented approach aimed at simplifying interoperable authorization decisions.

  • Authorization

    Decision Point

    The control point that decides whether an access request should be allowed, denied, or constrained.

  • Authorization

    Default Rejection Principle

    A principle stating that access must be denied unless it has been explicitly evaluated and allowed.

  • Authorization

    Discretionary Right

    A Discretionary Right is a legitimate right granted outside the standard modeled access framework.

  • Authorization

    Dynamic Guardrail

    A Dynamic Guardrail is a policy-based runtime control that blocks or constrains risky behavior in real time.

  • Authorization

    Emergency Override

    A security mechanism that allows immediate exceptional intervention on access rights during an incident.

  • Authorization

    Enforcement Point

    The control point that applies the decision made elsewhere.

  • Authorization

    Entitlement

    An entitlement is an assigned access right, privilege set, or application-specific grant that gives a subject effective access to functions, data, or resources.

  • Authorization

    Externalized Authorization

    Externalized Authorization is an access control model where applications delegate access decisions to a dedicated authorization service.

  • Authorization

    Fine-Grained Authorization

    Fine-grained authorization is the ability to make authorization decisions at a very detailed level, such as per object, field, action, relationship, or transaction condition.

    FGA