Quiz Entry - updated: 2026.09.17
What counts as "access" in IAM, and what are the typical operations?
Access is any operation you can perform on a resource; the typical ones are read, write (which includes changing, creating and deleting) and execute.
Access is deliberately defined as an operation, not as "opening a door", because the rules of authorisation are written in terms of operations: a subject may be allowed to read a file but not change it, or to execute a program but not read its source. The classic set is:
- Read
- Write, covering change, create and delete
- Execute
Real systems refine this into finer-grained verbs (approve, share, export, ...), but every such verb is still an operation on a resource, which is what an access rule ("subject may perform operation on resource under condition") refers to.