A successful login answers one question: who presented the credential?
It does not answer whether that identity may view a record, approve a payment, change a configuration, impersonate a user, or access another organization. Those decisions belong to authorization.
Systems become dangerous when identity is treated as unlimited permission.
Authorize Every Sensitive Action
Enforce authorization on the server for each protected operation.
Frontend visibility is a user-experience choice, not a security boundary. Hiding a button does not prevent a direct API request. Validate the actor, action, resource, organization, environment, and current state before performing the operation.
Default to denial when policy is missing or ambiguous.
Keep Context In The Decision
Roles alone are often too broad.
An administrator for one organization should not become an administrator for every tenant. A project member may view assets without being allowed to delete them. A support engineer may receive temporary diagnostic access without gaining data-export authority.
Use role, relationship, resource ownership, risk, and environment together where the decision requires them.
Test Negative Paths
Authorization tests should prove that forbidden actions fail.
Test cross-tenant access, changed identifiers, stale sessions, disabled accounts, downgraded roles, missing ownership, bulk endpoints, background jobs, exports, and administrative APIs. Include object-level authorization, not only route-level checks.
The most important test may be the action a user should never complete.
Observe Permission Decisions
Record high-risk grants, denials, policy changes, impersonation, and privileged actions. Avoid logging credentials or sensitive payloads. Make logs attributable and useful during investigation.
Authorization failures can reveal both attacks and broken product assumptions.
Run The Defense Test
State which identity is trusted and for what purpose. Define how permission is granted, reviewed, and removed. Limit access to the smallest resource and action. Preserve evidence of privileged decisions. Keep a recovery path for mistaken grants without bypassing policy.
Authentication opens the conversation. Authorization decides what happens next.