authorizations to execute
163604·updated Sep 1, 2026A compositional phrase, not a coined term of art, describing the set of permissions or access rights that a principal (user, process, or device) has been formally granted to run, invoke, or trigger an action — such as a transaction, script, program, or privileged command — on a system or resource. NIST SP 800-171 frames the underlying concept by requiring that system access be limited "to the types of transactions and functions that authorized users are permitted to execute." In access-control practice, authorizations are expressed as access policies — for example, in the form of an access control list or a capability — and a principal who "does not possess the authorizations to execute" a given action lacks an entry in those policies granting that right. Standards bodies such as NIST require that approved authorizations for logical access to information and system resources be enforced in accordance with applicable access control policies, so the phrase appears naturally in control language to describe the boundary condition where enforcement should block an attempted action.
Source
do not possess the authorizations to executethe sentence this term was read in
generalized from a web lookup of the quoted expression at proposal time Verdict: compositional.
- 3.1.5: Employ the principle of least privilege, including for specific security functions and privileged accounts - CSF Tools
- Authorization
- PR.AC-4: Access permissions and authorizations are managed, incorporating the principles of least privilege and separation of duties - CSF Tools
A definition generalized from search results is a draft to react to, not provenance. Confirm it against an authority document before this term is verified.
A web lookup ran when this term was proposed
A compositional phrase, not a term of art. It combines the ordinary security-field noun "authorization" (a permission or entitlement granted to a subject by a policy or authority) with the infinitive "to execute" (to run, invoke, or carry out an action, process, or function). In context it describes whether a given identity, account, or process holds the access rights required to run something — a program, command, privileged function, or transaction — and its meaning is fully recoverable from its parts without any specialized redefinition.
Advisory only. A term this product ships is defined by an authority document, not by a search result.
Proposed during multiword review of this document in the CKI mapping queue.
Attested in
Classifications
Entity Type
Sensitivity
Information Class
Variants
- plural
- authorizations to executes
- possessive
- authorizations to execute's
- pluralpossessive
- authorizations to executes'
Framework definitions
- §1 · attested_usage_reviewer_confirmed
- No definition is given in NIST SP 800-171r3. The term is attested in use at 1 citation in that document; a definition is pending curation.Increment 2: attested in 800-171r3 without a glossary definition.
- §1 · web_lookup_draft
- A compositional phrase, not a coined term of art, describing the set of permissions or access rights that a principal (user, process, or device) has been formally granted to run, invoke, or trigger an action — such as a transaction, script, program, or privileged command — on a system or resource. NIST SP 800-171 frames the underlying concept by requiring that system access be limited "to the types of transactions and functions that authorized users are permitted to execute." In access-control practice, authorizations are expressed as access policies — for example, in the form of an access control list or a capability — and a principal who "does not possess the authorizations to execute" a given action lacks an entry in those policies granting that right. Standards bodies such as NIST require that approved authorizations for logical access to information and system resources be enforced in accordance with applicable access control policies, so the phrase appears naturally in control language to describe the boundary condition where enforcement should block an attempted action.DR-088 backfill from the noun definition column