The author argues that authorization models like RBAC, ABAC, and PBAC are often misclassified due to a lack of understanding of the different axes involved in an authorization system. The six axes include authority administration, authorization model, policy expression, access control mechanism, enforcement location and architecture.