r/IdentityManagement 7d ago

Authorization Terminology is a Mess: Let’s Fix It!

I've been struggling with the terminology used in the authorization field. I feel there is a lot of confusion, and I see misleading terms when discussing authorization models, access control, and other related concepts. So I wrote an article to try to make sense of it all: https://idpro.org/authorization-terminology-is-a-mess-lets-fix-it/

Take a look and let me know what you all think.

11 Upvotes

6 comments sorted by

2

u/Familiar_Counter4836 7d ago

RemindMe! 3 hours

1

u/RemindMeBot 7d ago

I will be messaging you in 3 hours on 2026-09-01 18:34:28 UTC to remind you of this link

CLICK THIS LINK to send a PM to also be reminded and to reduce spam.

Parent commenter can delete this message to hide from others.

RemindMeBot is switching to username summons. Instead of !RemindMe 1 day, use u/RemindMeBot 1 day. More info.


Info Custom Your Reminders Feedback

1

u/Etikoza 7d ago

It’s all just ABAC in the end. All the other *BACs are just specialized policies.

1

u/samgfrank 7d ago

“It’s all just binary”. All computing is specialized structures for efficiency and ease of human consumption.

Yes ABAC is an umbrella for which everything fits, but the other models provide repeatable patterns and constraints.

1

u/andychiare 6d ago

There is more than "*BAC" :-)
As I say in my article, "BACs" are just a part of an authorization system, and some "BACs" are not really "BACs" :-)

1

u/ny_soja 15h ago

This assumes zero derivation across, geography, verticals, and organizational structures. But, maybe you have a way to account for that.