Authorization Terminology Is a Mess: Let's Fix It

Authorization terminology has accumulated for decades, leading to confusion where terms like RBAC, ABAC, MAC, and PBAC are often compared as if they were competing models. This article argues they answer different questions and proposes a taxonomy of six axes, each addressing a distinct aspect of authorization systems: administration, model, policy, information, decision, and enforcement. By separating these concerns, familiar labels can be placed on the right axis, clarifying their relationships and reducing miscommunication.
Treating them as competing options is like comparing a recipe to a kitchen.
- jiggawatts
I love how the OIDC standard is littered with “authentication identity token code id cookie identifier” and many subtle variations of homonyms in slightly different combinations and orders.
I’m sure someone thought it all made perfect sense.
Probably someone who never confuses “empathy” and “sympathy” while also carefully distinguishing between “should” and “ought”.
- usernametaken29
Nice work and all regardless
- tuberreact
turns out naming is important
- andrewshadura
Unclosable cookie banner. Top notch website engineering.
- nekusar
Are you fixing it at the IETF and RFC level, or is this just another way to say "BUY OUR SHIT AND IT TOTALLLY SOLVES EVERYTHING!!!!11"