Quiz Entry - updated: 2026.09.17
What are the three kinds of resources by protection need, and which of them does IAM actually care about?
Public resources need no authentication, hidden resources need none either but are only known to a few, and protected resources require successful authentication and authorisation; IAM is generally concerned only with the protected kind.
| Kind | Access requirement | Example |
|---|---|---|
| Public (not worth protecting) | None, freely accessible | Read access to an informational website, open data |
| Hidden | No authentication, but the location is only known to a set of subjects | A Google Doc or Doodle poll shared by link: anyone who knows the URL gets in |
| Protected (non-public) | Successful authentication and authorisation of the accessing subject | Your e-banking, a company's HR files |
The hidden category is the interesting one because it shows that "secrecy of the address" is a form of access control, just a weak one: the URL acts as a shared secret with no way to revoke a single person's knowledge of it. That is why hidden resources are convenient for low-stakes sharing and unacceptable for anything sensitive, and why IAM proper starts at the protected category.