# Understanding the keycloak authorization over a Resource with negative logic

**URL:** <https://forum.keycloak.org/t/understanding-the-keycloak-authorization-over-a-resource-with-negative-logic/20672>\
**Category:** Getting advice\
**Created:** [March 6, 2023, 6:01pm UTC](https://forum.keycloak.org/t/understanding-the-keycloak-authorization-over-a-resource-with-negative-logic/20672 "2023-03-06T18:01:23Z")\
**Posts on this page:** 2\
**Page:** 1

<div class="post-metadata">

**Author:** ![JayanthC](https://avatars.discourse-cdn.com/v4/letter/j/7feea3/32.png) [@JayanthC](https://forum.keycloak.org/u/JayanthC)\
**Post date:** [March 6, 2023, 6:01pm UTC](https://forum.keycloak.org/t/understanding-the-keycloak-authorization-over-a-resource-with-negative-logic/20672/1 "2023-03-06T18:01:23Z")

</div>

Scenario 3:  
In this scenario we have 2 users and 1 resource Flow1. We have created one positive logic policy for one of the user and negative logic policy for another user. All the 3 permissions are granted for positive logic policy and only read permission/scope is added for the negative logic policy. The result for evaluating the negative policy is denied for all the permissions.

 ![Screenshots_1](https://global.discourse-cdn.com/free1/uploads/keycloak/original/2X/9/9478e7205715e206b2b8a6687ea546503880f631.jpeg)

---

<div class="post-metadata">

**Author:** ![JayanthC](https://avatars.discourse-cdn.com/v4/letter/j/7feea3/32.png) [@JayanthC](https://forum.keycloak.org/u/JayanthC)\
**Post date:** [March 6, 2023, 6:01pm UTC](https://forum.keycloak.org/t/understanding-the-keycloak-authorization-over-a-resource-with-negative-logic/20672/2 "2023-03-06T18:01:56Z")

</div>

Scenario 3 Evaluation results

 ![Screenshots_2](https://global.discourse-cdn.com/free1/uploads/keycloak/original/2X/c/c3d14a8d42e4d0d9402f447f0c607faa6f69522d.jpeg)
