Once identity is known, authorization decides which actions and resources the caller may access. Common models: role-based (RBAC — admin vs member), attribute-based (ABAC — rules over attributes), and scopes (OAuth tokens granting specific permissions). Enforce it on the server for every request — never trust the client to hide a button.