Authorization
RBAC, ABAC and ReBAC, and centralising the decision but not the enforcement.
5 to work through
-
advanced
A collaboration platform adds shared channels between separate customer organisations. What data-boundary problems does this create, and how should authorization be modelled?
3 min answer -
advanced
A document collaboration product needs sharing with individuals, teams, and inherited folder permissions. Which authorization model?
2 min answer -
advanced
A multi-tenant platform must guarantee that one customer can never see another's data. Where should that check live, and what makes the guarantee credible?
2 min answer -
advanced
A workspace product has pages nested arbitrarily deep, with permissions inheritable and overridable at any level, shared with individuals, groups and guests. How should authorization be designed so checks stay fast and correct?
2 min answer -
advanced
An internal API accepts a customer ID and returns that customer's data. It authenticates the calling service with mTLS. What is the flaw?
2 min answer
6 terms in this topic
Administrative Path Blindness
The pattern where the customer-facing data path is rigorously access-controlled while internal dashboards, support tools, analytics jobs and exports …
conceptConfused Deputy
A privileged component tricked into performing an action on behalf of a caller who lacks the authority to perform it directly.
conceptObject-Level Authorization
Checking that the caller is entitled to the specific record they requested, not merely that they may call the endpoint.
patternPer-Record Tenancy
Attaching the owning organisation to each record rather than to its container, so that data shared across tenant boundaries can still be governed, ex…
conceptRelationship-Based Access Control
Expressing permissions as relationships between subjects and objects, with inheritance and group expansion as rules over the graph, rather than as at…
conceptRole Explosion
The proliferation of narrowly-scoped roles that occurs when RBAC is used to express rules that actually depend on context.
Neighbouring topics
Security Architecture
General material on securing an architecture.
Authentication
Establishing who a principal is, and how strong that claim needs to be.
OAuth 2.0 & OIDC
Delegated authorisation, and the identity layer that makes login safe.
Tokens & JWTs
Stateless validation, revocation, and pinning the algorithm.
Identity & Access Management
Workload identity, roles, permission boundaries and usage-based review.
Secrets Management
Runtime injection, dynamic credentials and rotation applications survive.
Encryption
At rest, in transit, and at the application layer — three different threats.
Key Management
Rotation, separation of duty, envelope encryption and crypto-shredding.
Zero Trust
No implicit trust from network position; authorise every request.
Threat Modelling
Walking trust boundaries with STRIDE before anything is built.
OWASP Risks
The recurring web and API risk classes, several of which are design flaws.
Secure API Design
Object-level authorisation, input validation and safe error responses.
Supply Chain Security
Dependencies, SBOMs, build provenance and artefact signing.
Network Security
Segmentation, egress control and limiting lateral movement.
Auditability
Tamper-evident, attributed records that survive async boundaries.
Compliance Frameworks
SOC 2, ISO 27001, PCI DSS — scope as an architectural lever.
Privacy Engineering
Minimisation, purpose limitation, and erasure that is implementable.
Data Classification
Knowing which fields are regulated, because every control depends on it.
Security Incident Response
Detection, scoping, containment and notification clocks.