Authorization
Last updated:
Use these topics to understand Helium framework policies, provider-neutral evaluation, endpoint and operation protection, role and entitlement composition, and consumer-owned additive policies.
Warning
The public authorization contracts and normative policy matrix are established, but validated organization context, framework handlers, evaluator behavior, endpoint adapters, consumer composition guards, and readiness verification remain in progress in WS-005.
Start here
- Authorization model — Understand the deny-by-default evaluation stages.
- Framework authorization policies — Use stable identifiers and the Initial MVP role matrix.
- Evaluate organization authorization — Prepare integration against the provider-neutral evaluator.
Integration guidance
- Protect application operations
- Protect ASP.NET Core endpoints
- Combine roles and entitlements
- Define consumer policies
Troubleshooting
Use Authorization troubleshooting to diagnose missing context, policy denial, stale membership state, and configuration failures.