# Blog

## Company Updates & Technology Articles

**The final chapter for Aserto**  
Goodbye Aserto, long live Topaz.  
[Apr 27th, 2025](/content/blog/the-final-chapter-for-aserto/index.html)

**Stateless vs Stateful Authorization**  
The most important design decision for an authorization system is how to bring data to the engine. Read all about the tradeoffs.  
[Mar 27th, 2025](/content/blog/stateless-vs-stateful-authorization/index.html)

**AuthZEN, Gartner IAM, and native support in Topaz**  
OpenID AuthZEN defines an Authorization API that allows policy enforcement points to evaluate a decision in a standard way. Topaz now has native support for AuthZEN.  
[Feb 28th, 2025](/content/blog/authzen-gartner-iam-and-native-support-in-topaz/index.html)

**Centralized vs Distributed Authorization**  
What are the tradeoffs between running a central authorization service versus distributed authorizers?  
[Jan 23rd, 2025](/content/blog/centralized-vs-distributed-authorization/index.html)

**The Case for Centralizing Authorization**  
Why centralize authorization, what are the impediments, and how do you overcome them?  
[Jan 9th, 2025](/content/blog/the-case-for-centralizing-authorization/index.html)

**Authorization in 2024: Year in Review**  
As we ring in the new year, here’s a retrospective on authorization in 2024.  
[Dec 31st, 2024](/content/blog/authorization-in-2024-year-in-review/index.html)

**Authorization at Gartner IAM Summit 2024**  
Gartner IAM Summit is one of the top events in the identity universe, and Authorization is becoming a key pillar. Here’s our trip report.  
[Dec 12th, 2024](/content/blog/authorization-at-gartner-iam-summit-2024/index.html)

[Cloud-Native Authorization at KubeCon NA 2024](/content/blog/cloud-native-authorization-at-kubecon-na-2024/index.html)
[Building Permission-Aware Enterprise Chatbots](/content/blog/building-permission-aware-enterprise-chatbots/index.html)
[Authentication and authorization with Auth0 and Aserto](/content/blog/authentication-authorization-auth0-aserto/index.html)
[OpenID AuthZEN, One Year In: A Retrospective](/content/blog/openid-authzen-one-year-in-a-retrospective/index.html)
[Aserto at Authenticate 2024](/content/blog/aserto-at-authenticate-2024/index.html)
[API Authorization using Aserto and Zuplo](/content/blog/api-authorization-using-aserto-and-zuplo/index.html)
[OpenID AuthZEN Implementer's Draft and Why it Matters](/content/blog/openid-authzen-implementers-draft-why-it-matters/index.html)
[Authorization 101: Multi-tenant RBAC](/content/blog/authorization-101-multi-tenant-rbac/index.html)
[Adding Authorization to a Go app with Topaz](/content/blog/adding-authorization-to-a-go-app-with-aserto/index.html)
[Building RBAC in Go](/content/blog/building-rbac-in-go/index.html)
[Where should I enforce my authorization policy?](/content/blog/where-should-i-enforce-my-authorization-policy/index.html)
[Gateway-enforced API Authorization](/content/blog/gateway-enforced-api-authorization/index.html)
[An “easy button” for API Authorization](/content/blog/an-easy-button-for-api-authorization/index.html)
[Implementing Custom Roles in your SaaS Application](/content/blog/implementing-custom-roles-in-your-saas-application/index.html)
[Topaz Passes 1000 Stars on GitHub!](/content/blog/topaz-passes-1000-stars-on-github/index.html)
[OpenID Foundation AuthZEN Working Group Announces Interop Results](/content/blog/openid-foundation-authzen-working-group-announces-interop-results/index.html)
[Announcing Topaz 0.32!](/content/blog/announcing-topaz-0-32/index.html)
[The authorization 3-body problem](/content/blog/the-authorization-3-body-problem/index.html)
[Internet Identity Workshop 38: a retrospective](/content/blog/internet-identity-workshop-38-a-retrospective/index.html)
[How ReBAC helps solve data filtering](/content/blog/how-rebac-helps-solve-data-filtering/index.html)
[Modern application authorization: Insights from the trenches](/content/blog/modern-application-authorization-insights-from-the-trenches/index.html)
[Product pulse #7 - Authorization Templates and Directory Assertions](/content/blog/product-pulse-7-authorization-templates-and-directory-assertions/index.html)
[Authorize like GitHub: A real-world example of fine-grained authorization](/content/blog/authorize-like-github/index.html)
[Advancing authorization: Join Aserto at leading identity & access conferences in 2024](/content/blog/aserto-identity-authorization-conferences-2024/index.html)
[Authorization in Slack: A real-world example of RBAC with fine-grained controls](/content/blog/slack-authorization-example-rbac-with-fine-grained-controls/index.html)
[Announcing Topaz 0.31: our spiciest edition yet!](/content/blog/announcing-topaz-031/index.html)
[Addressing the complexities of fine-grained authorization for applications](/content/blog/fine-grained-authorization-applications-complexities/index.html)
[How Airbnb and Uber authorize their apps: Real-world examples of ReBAC and ABAC](/content/blog/airbnb-uber-app-authorization-rebac-abac-examples/index.html)
[Product Pulse #6: Aserto supports Active Directory and LDAP](/content/blog/aserto-supports-active-directory-ldap/index.html)
[Authorization and the principle of least privilege](/content/blog/authorization-principle-least-privilege/index.html)
[Unlocking modern, fine-grained authorization with Topaz](/content/blog/fine-grained-authorization-with-topaz/index.html)
[When do you need attributes in fine-grained authorization?](/content/blog/attributes-authorization-when-to-use/index.html)
[Why authorization decision logs are important](/content/blog/authorization-decision-logs-important/index.html)
[Getting started with modern authorization](/content/blog/getting-started-modern-authorization/index.html)
[Authorization library vs purpose-built authorization service](/content/blog/authorization-library-vs-service/index.html)
[The state of cloud-native technology and AI](/content/blog/cloud-native-authorization-ai-state-2023/index.html)
[Authorization - year in review](/content/blog/authorization-2023-review/index.html)
[Google vs Netflix’s approach to authorization: real-world examples of ReBAC and ABAC](/content/blog/google-vs-netflix-authorization-approach-rebac-abac-examples/index.html)
[Hard coded logic vs externalized authorization service](/content/blog/hardcoded-vs-externalized-authorization/index.html)
[Announcing Topaz 0.30!](/content/blog/announcing-topaz-030/index.html)
[Open Policy Agent vs Google Zanzibar](/content/blog/open-policy-agent-vs-google-zanzibar/index.html)
[It's time for authorization standards: AuthZEN](/content/blog/authorization-standards-authzen/index.html)
[Using scopes vs. permissions for application authorization](/content/blog/scopes-vs-permissions-authorization/index.html)
[The power of externalized authorization](/content/blog/externalized-authorization-power/index.html)
[Netflix authorizes extra members using environmental attributes](/content/blog/netflix-authorization-extra-members-environmental-attributes/index.html)
[Meet Aserto at Identity Week, Devopsdays, API World, Global AppSec, and KubeCon](/content/blog/aserto-sponsors-kubecon-identity-week-api-world-global-appsec/index.html)
[Introducing ds-load](/content/blog/introducing-dsload/index.html)
[Five open-source projects to secure access to your applications](/content/blog/five-oss-authentication-authorization-projects/index.html)
[Auth in everyday terms](/content/blog/authorization-in-everyday-terms/index.html)
[The future of IAM is fine-grained](/content/blog/fine-grained-authorization-future-iam/index.html)
[5 Ways to Fix Your Broken Authorization System](/content/blog/5-ways-fix-broken-authorization-systems/index.html)
[“Auth” demystified: authentication vs authorization](/content/blog/authentication-vs-authorization/index.html)
[Five ways Aserto helps you get started with fine-grained access controls](/content/blog/five-ways-aserto-helps-implement-fine-grained-authorization/index.html)
[Five common application authorization patterns](/content/blog/common-application-authorization-patterns/index.html)
[Going beyond RBAC: a modern authorization panel](/content/blog/going-beyond-rbac-modern-authorization-panel/index.html)
[Assessing New Threats Related to Broken Access](/content/blog/new-threats-broken-access-controls-2023/index.html)
[Why ReBAC is eating the authorization world](/content/blog/why-rebac-eating-modern-authorization/index.html)
[Product Pulse #5: Graph Visualizer, Java SDK, and new self-hosted options](/content/blog/product-pulse-graph-visualizer-java-sdk-self-hosted-directory-console/index.html)
[Adding authorization to a Java app with Aserto](/content/blog/adding-authorization-java-app-with-aserto/index.html)
[Cloud-native authorization on Category Visionaries](/content/blog/cloud-native-authorization-category-visionaries/index.html)
[Modern access control explained](/content/blog/modern-access-control-explained/index.html)
[A CISO’s perspective on application security](/content/blog/ciso-perspective-application-security/index.html)
[Aserto's cloud agnostic design for running production workloads across cloud providers](/content/blog/aserto-supports-multicloud-production-workloads/index.html)
[Building dynamic RBAC with custom roles for multi-tenant applications](/content/blog/building-dynamic-multitenant-rbac-custom-roles/index.html)
[OPA : Zanzibar :: SOAP : REST?](/content/blog/opa-zanzibar-soap-rest/index.html)
[Building a React and Node app with Aserto authorization](/content/blog/building-react-node-app-aserto-authorization/index.html)
[Using Identity Information from Azure Active Directory in Aserto](/content/blog/azure-active-directory-aserto-integration/index.html)
[Aserto sponsors EIC and Identiverse, and speaks at KubeCon EU](/content/blog/aserto-sponsors-eic-identiverse-2023/index.html)
[Five common authorization patterns](/content/blog/five-common-authorization-patterns/index.html)
[Solving cloud-native authorization](/content/blog/solving-cloud-native-authorization/index.html)
[A CISO Perspective on Enterprise Forensics: How to Get Back From a Breach](/content/blog/ciso-perspective-enterprise-forensics-get-back-from-breach/index.html)
[Product Pulse #4: New directory and authorizer, evaluator, and more!](/content/blog/product-pulse-new-directory-authorizer-evaluator/index.html)
[A secure software supply chain for OPA policies](/content/blog/secure-software-supply-chain-opa-policies/index.html)
[What Happens When Access Controls Fail](/content/blog/when-access-controls-fail/index.html)
[A CISO Perspective on Simplifying Compliance with Decision Logs](/content/blog/ciso-perspective-simplify-compliance-decision-logs/index.html)
[ABAC vs. ReBAC: comparing fine-grained access control models](/content/blog/abac-vs-rebac-fine-grained-access-control/index.html)
[A CISO Perspective on the Importance of Separating Authorization Policy and Application Code](/content/blog/ciso-perspective-importance-separating-policy-application-code/index.html)
[Cloud-native authorization on Techstrong TV](/content/blog/cloud-native-authorization-interview-techstrong-tv/index.html)
[RBAC vs ABAC: pros, cons, and example policies](/content/blog/rbac-vs-abac-authorization-models/index.html)
[A CISO perspective on Broken Access Control](/content/blog/broken-access-control-ciso-perspective/index.html)
[Goodbye Open Policy Registry, Hello Open Policy Containers!](/content/blog/goodbye-open-policy-registry-hello-open-policy-containers/index.html)
[How to avoid Broken Access Control vulnerabilities](/content/blog/avoid-broken-access-control-vulnerabilities/index.html)
[How Google Drive models authorization](/content/blog/google-zanzibar-drive-rebac-authorization-model/index.html)
[RBAC vs ReBAC: a comparison of authorization models with examples](/content/blog/rbac-vs-rebac/index.html)
[Aserto is SOC 2 Type II Compliant](/content/blog/aserto-soc2-compliant/index.html)
[The five laws of cloud-native authorization](/content/blog/5-laws-cloud-native-authorization/index.html)
[Open-source cloud-native authorization on theCUBE](/content/blog/oss-cloud-native-authorization-topaz/index.html)
[Topaz: an open-source cloud-native authorization solution combining the best of OPA and Zanzibar](/content/blog/topaz-oss-cloud-native-authorization-combines-opa-zanzibar/index.html)
[Cloud-native authorization at KubeCon](/content/blog/cloud-native-authorization-kubecon-2022/index.html)
[Deploying an Application to Kubernetes with an Aserto Sidecar](/content/blog/deploying-an-application-to-kubernetes-with-an-aserto-sidecar/index.html)
[The evolution of fine-grained access control](/content/blog/fine-grained-access-control-evolution/index.html)
[Access Control - Build vs. Buy](/content/blog/access-control-build-vs-buy/index.html)
[Implement Fine-Grained Security, or Get Left Behind](/content/blog/implement-fine-grained-security-or-get-left-behind/index.html)
[Product pulse #3 - The new Aserto Directory, CLI updates and Decision Logs from the Edge Authorizer](/content/blog/product-updates-september-15/index.html)
[RBAC, ABAC, and ReBAC - Differences and Scenarios](/content/blog/rbac-abac-and-rebac-differences-and-scenarios/index.html)
[The New Aserto Directory](/content/blog/new-aserto-directory/index.html)
[Adding Authorization to a Ruby on Rails Application](/content/blog/authorization-ruby-on-rails-application/index.html)
[Fine-grained access control at DeveloperWeek Cloud](/content/blog/developerweek-cloud-2022/index.html)
[Open-source authorization as a service](/content/blog/oss-access-control-system-as-service/index.html)
[Product pulse #2 - Edge Authorizer user interface enhancements, Ruby SDK, and a new Citadel demo identity provider](/content/blog/product-updates-september/index.html)
[Adding Authorization to An ASP.NET Application](/content/blog/authorization-dotnet-application/index.html)
[Product pulse #1 - Enhanced Edge Authorizer security, new ASP.NET quickstart, OPA update, and more](/content/blog/product-pulse-1/index.html)
[Adding Authorization to A Python Application](/content/blog/authorization-python-application/index.html)
[Why multi-tenant SaaS applications need real access control from day 1](/content/blog/multi-tenant-saas-applications-need-real-access-control-from-day-1/index.html)
[Adding Authorization to A Node.js Application](/content/blog/authorization-node-js-application/index.html)
[Securing the software supply chain for Policy-as-Code](/content/blog/securing-software-supply-chain-policy-as-code/index.html)
[mage-loot: Dependency management for Go](/content/blog/mage-loot-dependency-management-for-go/index.html)
[Aserto Console: June 2022 release notes](/content/blog/aserto-console-june-2022-release-notes/index.html)
[Policy-as-Code or Policy-as-Data? Why choose?](/content/blog/policy-as-code-or-policy-as-data-why-choose/index.html)
[OPA natively consumers OCI images](/content/blog/opa-natively-consumes-oci-images/index.html)
[Aserto delivers access control by bringing together cloud-native ecosystems](/content/blog/aserto-access-control-cncf/index.html)
[Policy-as-Code for Docker and Kubernetes with Conftest or Gatekeeper](/content/blog/policy-as-code-for-docker-and-kubernetes-with-conftest-gatekeeper/index.html)
[Feature Review: Decision Logging](/content/blog/feature-review-decision-logging/index.html)
[Creating a Rego policy for a Todo application](/content/blog/creating-a-rego-policy-for-a-todo-application/index.html)
[GitLab Integration is here!](/content/blog/gitlab-integration-is-here/index.html)
[The Policy CLI and Github Packages](/content/blog/the-policy-cli-and-github-packages/index.html)
[Aserto sponsors KubeCon](/content/blog/aserto-sponsors-kubecon-and-cloudnativecon-events/index.html)
[How do Aserto Rego policies work?](/content/blog/how-do-aserto-rego-policies-work/index.html)
[Aserto Edge Authorizers](/content/blog/aserto-edge-authorizers/index.html)
[Testing Rego policies](/content/blog/testing-rego-policies/index.html)
[Flask RBAC demystified: a developer's guide](/content/blog/flask-rbac-demystified-a-developer-s-guide/index.html)
[Aserto, the developer API for permissions and RBAC, is open to all!](/content/blog/aserto-the-developer-api-for-permissions-and-rbac-is-open-to-all/index.html)
[How hard can authorization be?](/content/blog/how-hard-can-authorization-be/index.html)
[Building RBAC in Node](/content/blog/building-rbac-in-node/index.html)
[Isn't authorization part of authentication?](/content/blog/isnt-authorization-part-of-authentication/index.html)
[From RBAC to ABAC](/content/blog/from-rbac-to-abac/index.html)
[Authorization: Library or service?](/content/blog/authorization-library-or-service/index.html)
[The challenges of using OPA for application authorization](/content/blog/the-challenges-of-using-opa-for-application-authorization/index.html)
[Three essential RBAC best practices](/content/blog/3-essential-rbac-best-practices/index.html)
[Adding Aserto Authorization to React and Node app](/content/blog/building-a-react-and-node-app-with-aserto-authorization/index.html)
[Modern authorization requires defense in depth](/content/blog/modern-authorization-requires-defense-in-depth/index.html)
[Fine-grained authorization: what’s all the buzz about?](/content/blog/fine-grained-authorization-whats-all-the-buzz-about/index.html)
[Handling data in OPA policies](/content/blog/handling-data-in-opa-policies/index.html)
[Introducing the Open Policy Registry (OPCR) project](/content/blog/introducing-the-open-policy-registry-project/index.html)
[Composing OPA solutions](/content/blog/composing-opa-solutions/index.html)
[Aserto on Aserto: an OPA authorization policy for Aserto tenants](/content/blog/aserto-on-aserto-an-opa-authorization-policy-for-aserto-tenants/index.html)
[sver: Easy semantic versioning of your artifacts](/content/blog/sver-easy-semantic-versioning-of-your-artifacts/index.html)
[Rego: getting started](/content/blog/rego-getting-started/index.html)
[Addressing challenges with Github's authorization model](/content/blog/addressing-challenges-with-github-authorization-model/index.html)
[The Architectural Challenge of Authorization](/content/blog/the-architectural-challenge-of-authorization/index.html)
[Welcome to modern authorization](/content/blog/welcome-to-modern-authorization/index.html)
[OAuth2 scopes are NOT permissions](/content/blog/oauth2-scopes-are-not-permissions/index.html)
[Authentication != Authorization](/content/blog/authorization-is-not-authentication/index.html)
[The five principles of authorization](/content/blog/five-principles-of-authorization/index.html)
[Why separate policy from your code?](/content/blog/why-separate-policy-from-your-code/index.html)
[Authorization is broken](/content/blog/authorization-is-broken/index.html)
