User
In short: A person (or a system) who holds an account or actively uses an application or a service.
In more detail: In software development, a distinction is made between the real human and the “user” record representing them in the system (identity, rights, stored settings). User management typically covers authentication (who are you?) and authorisation (what are you allowed to do?).
In Depth
The difference between authentication and authorisation is often confused, but is fundamental:
- Authentication (“who are you?”): proving that someone really is who they claim to be — e.g. via password, 2FA, or public-key methods.
- Authorisation (“what are you allowed to do?”): checking whether an already-authenticated user is allowed to perform a particular action — e.g. whether a normal user is allowed to see admin functions.
A system can correctly authenticate someone (they really are who they claim to be) and still deny them a particular action via authorisation. In practice, this is often represented via roles (“role-based access control”, RBAC): every user is assigned one or more roles (e.g. “admin”, “moderator”, “customer”), and every role defines which actions are allowed — instead of granting rights individually for every single user.
Technically, a user in the system is usually represented via a unique ID, not via their name or email address (which can change) — all associated data (orders, settings, permissions) hangs off this ID, not off the changeable contact details.
See also: Authentication