Getting Started
Start with Protect your first app. The walkthrough connects a portal to an authorization policy and runs the policy before a protected response. One demo user has the required role and the other does not.
Then verify access: an unauthenticated request should
redirect to login, Alice should reach the app, and Bob should receive 403.
For an existing deployment, go to authorization guides or the policy syntax reference. Keep authentication and authorization separate: identifying a user does not establish that they may access every route.