This document provides an overview of VA's plans to establish an enterprise authorization service. It discusses current limitations around a lack of centralized policy management and standardized authorization solutions. The future state aims to define standards for role-based access control (RBAC), attribute-based access control (ABAC), and hybrid models. It also outlines establishing governance, identifying relevant attributes, and assessing applications' access control requirements in order to provide consistent authorization across VA applications and meet compliance needs. Use cases demonstrate conditional data access and restricting RBAC using ABAC attributes.