A practical guide to the 5 authorization gaps that drive access control audit findings in regulated enterprises. Covers scattered authorization logic, proof of enforcement, role versus permission reviews, non-human identity governance, and AI agent authorization, with concrete steps to fix each one.