Authorization is the process of determining what an authenticated user is allowed to access or do within an application. After a user’s identity has been verified through authentication, authorization rules can control access to specific screens, data, features, or actions based on the user’s account, role, permissions, or other predefined conditions.
Authorization helps ensure that users can access only the information and functionality intended for them. This is especially important for mobile applications that contain personal data, customer accounts, employee information, administrative functionality, payments, or other restricted content. Authentication confirms who the user is, while authorization determines what that user is permitted to do.
A company creates a mobile app for employees. All employees authenticate using their accounts, but authorization rules determine which information they can access. Regular employees can view company documents and news, while users with additional permissions can access administrative functionality.