Authentication and authorization on the Build Your Own AI Platform track. Callers authenticate. Authorization decides which models and which data they may use. Training permissions are separate from inference permissions.
This lesson assumes you already worked through A gateway in front of models.
The idea in practice
Use short-lived tokens. Audit admin actions. A person who can promote should be a small group.
A concrete check
goal = {
'track': 'Build Your Own AI Platform',
'lesson': 'Authentication and authorization',
}
checks = [
'input available at decision time',
'score matches the real decision',
'failure case written down',
]
print(goal['lesson'])
for item in checks:
print('-', item)
Run the sketch locally if you have Python. The printout is a reminder of the checks, not a trained model. Replace the strings with the real inputs from your own example before you treat it as a design.
What usually goes wrong
One shared API key for the whole company. When this happens, stop adding parameters or tools. Fix the check, the data, or the permission, then run the same example again.
What to write down
- The input you are allowed to use at decision time.
- The output and the score or pass rule.
- One failure you will test on purpose.
- What you will not claim the system can do.
Practice
Separate three roles: trainer, promoter, caller.
Self-check
- Say Authentication and authorization in one sentence that mentions an input and an output.
- Name the failure mode in this lesson and the check that would catch it.
Done when: you can explain this lesson without the page open, and you have a written failure case.