Access Control
Access control is the broader security discipline that enforces authorization rules on access to resources, actions, and data.
Explore the concepts used across Identity and Access Management, Identity Governance, Access Management, privileged access, authorization and identity security.
Definitions are organized to support search and navigation between related concepts.
Access control is the broader security discipline that enforces authorization rules on access to resources, actions, and data.
Access Remediation is the process of correcting inappropriate, excessive, conflicting, or unjustified access.
Access Simulation is the evaluation of the effect of a proposed access change before it is actually granted.
A control layer that secures and governs API traffic, especially for machine-to-machine access.
Application SoD is the detection of toxic combinations of rights within a single application.
Attribute-Based Access Control, or ABAC, is an authorization model that makes decisions based on attributes of the subject, resource, action, and environment.
Authorization is the process of determining what an authenticated subject is allowed to do on a given resource under specific conditions.
Authorization Management is the IAM domain responsible for defining and enforcing what authenticated identities are allowed to do.
An Authorization Management Platform, or AMP, is a platform approach used to manage fine-grained authorization across multiple systems and applications.
An Authorization Matrix is a structured mapping of functions or actions against roles or user populations to show who may do what.
An authorization policy is a formal rule set that defines the conditions under which access should be allowed, denied, constrained, or escalated.
An Authorization Scope Dimension is a structured parameter used to define the perimeter within which an access right applies.
AuthZen is a standards-oriented approach aimed at simplifying interoperable authorization decisions.
A Binary Authorization Decision is a direct permit-or-deny answer to a specific access question.
The control point that decides whether an access request should be allowed, denied, or constrained.
A principle stating that access must be denied unless it has been explicitly evaluated and allowed.
A Discretionary Right is a legitimate right granted outside the standard modeled access framework.
A Dynamic Guardrail is a policy-based runtime control that blocks or constrains risky behavior in real time.
A security mechanism that allows immediate exceptional intervention on access rights during an incident.
The control point that applies the decision made elsewhere.
An entitlement is an assigned access right, privilege set, or application-specific grant that gives a subject effective access to functions, data, or resources.
A principle stating that access decisions must consider the wider activity context, not just the isolated request.
Externalized Authorization is an access control model where applications delegate access decisions to a dedicated authorization service.
Fine-grained authorization is the ability to make authorization decisions at a very detailed level, such as per object, field, action, relationship, or transaction condition.