Authorization Terminology Is a Mess: Let's Fix It

Authorization Terminology Is a Mess: Let's Fix It

Authorization terminology has accumulated for decades, leading to confusion where terms like RBAC, ABAC, MAC, and PBAC are often compared as if they were competing models. This article argues they answer different questions and proposes a taxonomy of six axes, each addressing a distinct aspect of authorization systems: administration, model, policy, information, decision, and enforcement. By separating these concerns, familiar labels can be placed on the right axis, clarifying their relationships and reducing miscommunication.

Treating them as competing options is like comparing a recipe to a kitchen.
  1. jiggawatts

    I love how the OIDC standard is littered with “authentication identity token code id cookie identifier” and many subtle variations of homonyms in slightly different combinations and orders.

    I’m sure someone thought it all made perfect sense.

    Probably someone who never confuses “empathy” and “sympathy” while also carefully distinguishing between “should” and “ought”.

  2. usernametaken29

    https://xkcd.com/927

    Nice work and all regardless

  3. tuberreact

    turns out naming is important

  4. andrewshadura

    Unclosable cookie banner. Top notch website engineering.

  5. nekusar

    Are you fixing it at the IETF and RFC level, or is this just another way to say "BUY OUR SHIT AND IT TOTALLLY SOLVES EVERYTHING!!!!11"

More from this day

2026-09-04