Authorization or
authorisation is the function of specifying access rights to resources related to
information security and
computer security in general and to
access control in particular. More formally, "to authorize" is to define an access policy. For example,
human resources staff is normally authorized to access employee records and this policy is usually formalized as access control rules in a computer system. During operation, the system uses the access control rules to decide whether access requests from (
authenticated) consumers shall be approved (granted) or disapproved (rejected). Resources include individual files or an item's
data,
computer programs, computer
devices and functionality provided by
computer applications. Examples of consumers are computer users, computer programs and other devices on the computer.