Authorize, don't authenticate
This article proposes a fundamental shift in how web applications manage user data: moving from authentication-based access (where users prove identity to applications) to authorization-based access (where users control their own databases and grant applications permission to use them). By decoupling applications from data storage through open protocols like OAuth2, users gain ownership and control of their data while reducing the risk of vendor lock-in, data breaches, and unauthorized data exploitation. For IT organizations, this represents an emerging architectural pattern that could reshape data governance, reduce security surface areas, and shift liability away from application providers toward user-controlled or federated database custodians.
