Quiz Entry - updated: 2026.09.17
Who decides about authorisation, on what basis, and which models and standards are most common today?
The application (relying party) decides whether an authenticated user may access a resource, by applying stored access rules at runtime; the dominant models are role-based (RBAC) and attribute-based access control (ABAC), and XACML is the standard language for describing the policies.
Authorisation is the third core process and it is owned by the relying party, not by the identity provider: the IdP can say "this is Alice, an employee", but only the HR application knows that employees may read their own personnel file and managers may read those of their reports.
- The rules must be stored beforehand (definition time) and are applied at runtime.
- RBAC, role-based access control: permissions are attached to roles (employee, manager), subjects get roles.
- ABAC, attribute-based access control: rules compare attributes of subject, resource and context ("department of subject equals department of document").
- XACML (eXtensible Access Control Markup Language) is the standard for writing such policies in a machine-readable form.
Synonyms: access control, user permission (Benutzerberechtigung).
Go deeper:
Role-based access control (Wikipedia) — roles, permissions and the NIST RBAC model levels.
XACML (Wikipedia) — the policy language and its PEP/PDP architecture for evaluating attribute-based rules.
NIST RBAC project — the standard's home at NIST: model levels, FAQ and case studies.
NIST SP 800-162 Guide to Attribute Based Access Control — the reference definition of ABAC and how it differs from role-based control.