1. Fortinet FortiOS 7.0.0 Administration Guide:
Section: "Building the Security Fabric" > "Adding a downstream FortiGate"
Page 100: "On the upstream FortiGate
go to Security Fabric > Fabric Connectors. A notification banner is displayed
indicating that a device is waiting for authorization... Select the FortiGate and click Authorize." This explicitly states that authorization is performed on the upstream (root) FortiGate.
2. Fortinet FortiOS 7.2.0 Administration Guide:
Section: "Security Fabric" > "Security Fabric settings"
Page 101: "When a device is configured to join the Security Fabric
the root FortiGate receives a request to authorize the device. The administrator must authorize the device from the root FortiGate to allow it to join the Security Fabric." This confirms the root FortiGate is the point of authorization.
3. Fortinet NSE 4 - FortiOS 7.2 Study Guide:
Module: "Security Fabric"
Page 10: "After you configure a FortiGate as a downstream device
you must authorize it on the root FortiGate." This reinforces that the authorization action is a mandatory step performed on the root device.