Authentication (Authentication) establishes who is asking; authorization decides what they may do. Laravel 2,157 has two tools on one engine, the Gate: a gate is a named closure for an action tied to no model, such as opening the staff dashboard, and a policy is a class holding the rules for one model, such as who may edit a Review. Every check, from a controller, route, Blade template or form request (Form Requests), ends in Gate::raw(), which runs these steps:

The examples add a role column to users (customer, staff or admin), orders and reviews owned by users, and five accounts: Ann and Ben (customers with an order each), Cal (a customer with none), Sam (staff) and Ada (admin). User::hasRole(string ...$roles) is a one-line in_array(), and the database is SQLite 4,756 , since nothing here is MySQL-specific.