Trust service catalogue
Authorize
Evaluate identity, role, entitlement, device and risk to make an authorization decision.
Which action may this person perform?
Check role and operator certification before granting machine access.
Purpose & scope
Evaluate identity, role, entitlement, device and risk to make an authorization decision.
Identity is bound to an authoritative source within an organization. Search population and access rights must be configured in advance.
From request to decision
Checks are bound to the same session.
Deployment-specific assurance
Do not use one threshold indiscriminately across devices and contexts.
| Component | Evaluation requirement | Evidence |
|---|---|---|
| PAD | Attack scope and evaluated configuration | Device / algorithm evaluation report |
| Performance | Threshold, test population, gallery, environment | Versioned evaluation profile |
| Device | Fresh session, certificate and revocation state | Device and configuration records |
| Authority & purpose | Processing basis and resource authorization | Policy version |