home/glossary/approved authorization

approved authorization

nounverified·updated Aug 30, 2026

A set of access permissions or privileges — granted to users, programs, or processes — that has been formally sanctioned through an organization's governance process (e.g., by a manager, system owner, or authorizing official) in accordance with applicable policy. What distinguishes it from authorization in general is the explicit "approved" qualifier: the rights must have passed through a defined review and approval workflow before they may be acted upon, tying individual entitlements back to a documented decision rather than informal or self-granted access. In practice, standards bodies such as NIST use the expression as the object of enforcement controls — systems must "enforce approved authorizations for logical access to information and system resources in accordance with applicable access control policies" — and equally as the basis for controlling information flows, as in controlling "the flow of CUI in accordance with approved authorizations." The expression is compositional in structure (adjective + noun), but it functions as a recurring technical phrase of art within NIST's access-control family, where authorization means "access privileges granted to a user, program, or p

MWELegacy lexicon import

Senses

NIST SP 800-171r3attested usage reviewer confirmed

No definition is given in NIST SP 800-171r3. The term is attested in use at 2 citations in that document; a definition is pending curation.

Classifications

Entity Type

Control92%llm-generatedllm:claude-haiku-4-5
?unassignedlast reviewed

Sensitivity

Regulated88%rule-basedr:sens.regulated.framework.v1
?unassignedlast reviewed

Information Class

Cui75%llm-generatedllm:claude-haiku-4-5
?unassignedlast reviewed

Variants

plural
approved authorizations
possessive
approved authorization's
pluralpossessive
approved authorizations'