Blog - Aserto
Blog
Company Updates & Technology Articles
The final chapter for Aserto
Goodbye Aserto, long live Topaz.
Apr 27th, 2025
Stateless vs Stateful Authorization
The most important design decision for an authorization system is how to bring data to the engine. Read all about the tradeoffs.
Mar 27th, 2025
AuthZEN, Gartner IAM, and native support in Topaz
OpenID AuthZEN defines an Authorization API that allows policy enforcement points to evaluate a decision in a standard way. Topaz now has native support for AuthZEN.
Feb 28th, 2025
Centralized vs Distributed Authorization
What are the tradeoffs between running a central authorization service versus distributed authorizers?
Jan 23rd, 2025
The Case for Centralizing Authorization
Why centralize authorization, what are the impediments, and how do you overcome them?
Jan 9th, 2025
Authorization in 2024: Year in Review
As we ring in the new year, here’s a retrospective on authorization in 2024.
Dec 31st, 2024
Authorization at Gartner IAM Summit 2024
Gartner IAM Summit is one of the top events in the identity universe, and Authorization is becoming a key pillar. Here’s our trip report.
Dec 12th, 2024
Cloud-Native Authorization at KubeCon NA 2024 Building Permission-Aware Enterprise Chatbots Authentication and authorization with Auth0 and Aserto OpenID AuthZEN, One Year In: A Retrospective Aserto at Authenticate 2024 API Authorization using Aserto and Zuplo OpenID AuthZEN Implementer's Draft and Why it Matters Authorization 101: Multi-tenant RBAC Adding Authorization to a Go app with Topaz Building RBAC in Go Where should I enforce my authorization policy? Gateway-enforced API Authorization An “easy button” for API Authorization Implementing Custom Roles in your SaaS Application Topaz Passes 1000 Stars on GitHub! OpenID Foundation AuthZEN Working Group Announces Interop Results Announcing Topaz 0.32! The authorization 3-body problem Internet Identity Workshop 38: a retrospective How ReBAC helps solve data filtering Modern application authorization: Insights from the trenches Product pulse #7 - Authorization Templates and Directory Assertions Authorize like GitHub: A real-world example of fine-grained authorization Advancing authorization: Join Aserto at leading identity & access conferences in 2024 Authorization in Slack: A real-world example of RBAC with fine-grained controls Announcing Topaz 0.31: our spiciest edition yet! Addressing the complexities of fine-grained authorization for applications How Airbnb and Uber authorize their apps: Real-world examples of ReBAC and ABAC Product Pulse #6: Aserto supports Active Directory and LDAP Authorization and the principle of least privilege Unlocking modern, fine-grained authorization with Topaz When do you need attributes in fine-grained authorization? Why authorization decision logs are important Getting started with modern authorization Authorization library vs purpose-built authorization service The state of cloud-native technology and AI Authorization - year in review Google vs Netflix’s approach to authorization: real-world examples of ReBAC and ABAC Hard coded logic vs externalized authorization service Announcing Topaz 0.30! Open Policy Agent vs Google Zanzibar It's time for authorization standards: AuthZEN Using scopes vs. permissions for application authorization The power of externalized authorization Netflix authorizes extra members using environmental attributes Meet Aserto at Identity Week, Devopsdays, API World, Global AppSec, and KubeCon Introducing ds-load Five open-source projects to secure access to your applications Auth in everyday terms The future of IAM is fine-grained 5 Ways to Fix Your Broken Authorization System “Auth” demystified: authentication vs authorization Five ways Aserto helps you get started with fine-grained access controls Five common application authorization patterns Going beyond RBAC: a modern authorization panel Assessing New Threats Related to Broken Access Why ReBAC is eating the authorization world Product Pulse #5: Graph Visualizer, Java SDK, and new self-hosted options Adding authorization to a Java app with Aserto Cloud-native authorization on Category Visionaries Modern access control explained A CISO’s perspective on application security Aserto's cloud agnostic design for running production workloads across cloud providers Building dynamic RBAC with custom roles for multi-tenant applications OPA : Zanzibar :: SOAP : REST? Building a React and Node app with Aserto authorization Using Identity Information from Azure Active Directory in Aserto Aserto sponsors EIC and Identiverse, and speaks at KubeCon EU Five common authorization patterns Solving cloud-native authorization A CISO Perspective on Enterprise Forensics: How to Get Back From a Breach Product Pulse #4: New directory and authorizer, evaluator, and more! A secure software supply chain for OPA policies What Happens When Access Controls Fail A CISO Perspective on Simplifying Compliance with Decision Logs ABAC vs. ReBAC: comparing fine-grained access control models A CISO Perspective on the Importance of Separating Authorization Policy and Application Code Cloud-native authorization on Techstrong TV RBAC vs ABAC: pros, cons, and example policies A CISO perspective on Broken Access Control Goodbye Open Policy Registry, Hello Open Policy Containers! How to avoid Broken Access Control vulnerabilities How Google Drive models authorization RBAC vs ReBAC: a comparison of authorization models with examples Aserto is SOC 2 Type II Compliant The five laws of cloud-native authorization Open-source cloud-native authorization on theCUBE Topaz: an open-source cloud-native authorization solution combining the best of OPA and Zanzibar Cloud-native authorization at KubeCon Deploying an Application to Kubernetes with an Aserto Sidecar The evolution of fine-grained access control Access Control - Build vs. Buy Implement Fine-Grained Security, or Get Left Behind Product pulse #3 - The new Aserto Directory, CLI updates and Decision Logs from the Edge Authorizer RBAC, ABAC, and ReBAC - Differences and Scenarios The New Aserto Directory Adding Authorization to a Ruby on Rails Application Fine-grained access control at DeveloperWeek Cloud Open-source authorization as a service Product pulse #2 - Edge Authorizer user interface enhancements, Ruby SDK, and a new Citadel demo identity provider Adding Authorization to An ASP.NET Application Product pulse #1 - Enhanced Edge Authorizer security, new ASP.NET quickstart, OPA update, and more Adding Authorization to A Python Application Why multi-tenant SaaS applications need real access control from day 1 Adding Authorization to A Node.js Application Securing the software supply chain for Policy-as-Code mage-loot: Dependency management for Go Aserto Console: June 2022 release notes Policy-as-Code or Policy-as-Data? Why choose? OPA natively consumers OCI images Aserto delivers access control by bringing together cloud-native ecosystems Policy-as-Code for Docker and Kubernetes with Conftest or Gatekeeper Feature Review: Decision Logging Creating a Rego policy for a Todo application GitLab Integration is here! The Policy CLI and Github Packages Aserto sponsors KubeCon How do Aserto Rego policies work? Aserto Edge Authorizers Testing Rego policies Flask RBAC demystified: a developer's guide Aserto, the developer API for permissions and RBAC, is open to all! How hard can authorization be? Building RBAC in Node Isn't authorization part of authentication? From RBAC to ABAC Authorization: Library or service? The challenges of using OPA for application authorization Three essential RBAC best practices Adding Aserto Authorization to React and Node app Modern authorization requires defense in depth Fine-grained authorization: what’s all the buzz about? Handling data in OPA policies Introducing the Open Policy Registry (OPCR) project Composing OPA solutions Aserto on Aserto: an OPA authorization policy for Aserto tenants sver: Easy semantic versioning of your artifacts Rego: getting started Addressing challenges with Github's authorization model The Architectural Challenge of Authorization Welcome to modern authorization OAuth2 scopes are NOT permissions Authentication != Authorization The five principles of authorization Why separate policy from your code? Authorization is broken