Authdog

Authorization

Last updated Sep 3, 2026
View as Markdown

Authorization decides what a signed-in identity may do in this environment. Pick one model. The other models' config is kept if you switch.

Models

  • RBAC (default) — roles carry CRUD on resources. Groups inherit roles.
  • ABAC — Rego policies over user, resource, and environment attributes.
  • FGA — relationship tuples, Zanzibar-style.

Start with RBAC. Move to ABAC when the decision depends on request context. Move to FGA when permissions inherit through a graph.

The rail changes with the model: RBAC shows Resources / Roles / Groups. ABAC shows Policies. FGA shows Relationships.

From the app

The check does not change when you switch models. Use the AuthZEN decision API or the SDK. See Roles & permissions, FGA, and AuthZEN.

Read To learn how to
Authorization concepts Compare the three models
Users Assign roles and groups
Audit Review access decisions

Learn more