Authorization checks whether an identity may perform a particular action on a resource. The server must consider the target, action, and ownership rather than just the presence of a login session.
The same signed-in user can open their own document while access to another user’s document is denied. Hiding a button in the UI is not a substitute for server-side checks on every route.
When to use
Apply it to APIs, files, documents, and administrative functions with per-user access rules.