The application evaluates roles, attributes, ownership, scopes, or explicit policy against the requested operation. Checks must run on the trusted server for every protected action rather than relying on hidden interface controls. Denials should avoid revealing sensitive resource details.