Authentication answers “who are you?” (prove identity). Authorization answers “what are you allowed to do?” (permissions) after you’re authenticated.