Authorize
To authorize is to give official approval or permission for an action, typically by a person or body that holds the recognized authority to do so. In a governance context, it commonly involves granting someone the right to act or approving that a specific activity may proceed. Authorization can also mean delegating power or decision rights to another party.
In governance and control terms, to authorize is to grant formal approval or permission for an activity, transaction, or access right by a party vested with the appropriate authority, often as defined by an organization's structure of decision rights and delegated authorities. Authorization typically functions as a control point that establishes who may legitimately initiate, approve, or execute a given action, and is commonly distinguished from the subsequent execution or recording of that action. General-language sources describe the term as endorsing, empowering, permitting, or delegating power by or as if by a recognized or proper authority; the specific scope, thresholds, and delegation arrangements vary by organization, jurisdiction, and applicable policy. This entry addresses the general governance meaning and does not cover implementation specifics, technical access-control mechanisms, or unrelated proper-noun uses such as the payment gateway 'Authorize.Net'.
Why it matters
Authorization is a foundational governance control because it establishes who holds the legitimate authority to permit an action, transaction, or access right to proceed. Without a clear structure of decision rights and delegated authorities, organizations risk actions being initiated or approved by parties who lack the standing to do so, undermining accountability and the integrity of decision-making. In many organizations, authorization functions as a defined control point that signals a deliberate approval has been given by a party vested with the appropriate authority.
Authorization is commonly distinguished from the execution and recording of the action it permits. This separation supports segregation of duties, a principle in which the person who approves an activity is not the same person who carries it out or records it, reducing opportunities for error or misuse. Where authorization thresholds, delegated authority limits, and approval workflows are ambiguous or poorly documented, controls may fail to operate as intended.
The specific scope, thresholds, and delegation arrangements associated with authorization vary by organization, jurisdiction, and applicable policy. As a result, what constitutes valid authorization in one setting may not translate directly to another, and governance professionals typically look to an organization's own structure of decision rights to determine whether an action was properly authorized.
Who it's relevant to
Inside Authorize
Common questions
Answers to the questions practitioners most commonly ask about Authorize.
