That sounds more like Authentication (verify identity) than Authorization (decide specifically what they are allowed to do per request), no?
e.g. You are Dave@customer.io (or some other verified identity), I know you, but how many SMS messages should I allow you to send via Vonage or Twilio when you click the button in the app? Managing that quota is an example of authorization.