Methods and apparatus, including computer program products, related to
relationship-based authorization. In general, data characterizing a
request for authorization to a computer-based resource is received, and
the authorization may be provided based on one or more relationships of a
requesting principal. A determination may be made as to whether a
requesting principal is authorized, which may include determining whether
the requesting user has a relationship with a principal that has
management rights of the computer-based resource and determining whether
the relationship allows for an access, such as a use of the
computer-based resource, if the requesting principal has a relationship
with the other principal. If there is no such relationship, a
determination may be made as to whether an organization of the requesting
principal has a relationship with the other principal that allows for the
access.