Our State of Authorization: AI Edition is now available Get it now »

2024 wrapped and looking ahead to 2025

We recap the highlights of 2024 in authorization and look ahead to what we have planned throughout 2025.

As we step into 2025, it’s the perfect time to reflect on the transformative strides made in authorization over the past year. This year has been a turning point, with significant developments shaping how organizations manage access control and secure sensitive data. From advancements in standards like the AuthZEN Working Group gaining momentum to the impactful role of AI in streamlining policy creation, 2024 has been a pivotal year.

Join us as we recap the highlights of 2024 and look ahead to what we have planned for 2025.

2024 A year in review

Looking back at 2024, a lot happened in the world of authorization. But three key topics stand out in our minds.

1. The year of standards

If you look at authorization standards between 2015 and 2023, it was a relatively quiet period. However, in 2023, we participated in the creation of the OpenID AuthZEN Working Group. The group’s key deliverables include a request/response standard for authorization requests, a set of design patterns, and education material.

In 2024, the group truly took off. We now have implementers and draft status, which marks a significant milestone in making authorization easy for organizations to deploy and operate across their entire application estates.

A side effect of working in the group is the community we’ve built within the authorization vendor space. We’ve engaged with our peers to improve the deployability, scalability, and interoperability of dynamic, fine-grained authorization, which has been an inspiring development.

2. Evolution of AI

Generative AI has seen significant growth over the past two years, although enterprises are still figuring out how to securely adopt it while mitigating potential threats. Key challenges include ensuring the security of the data used to train large language models and responsibly using corporate information for AI-generated outputs.

We’re only at the beginning of understanding how this will evolve. This is where authorization can come into play as organizations have to start thinking about the consequences for privacy, for data access, for where the data resides, how it’s being used, what insights you’re building off of that data. Essentially, you want to control access to what data AI can use.

We also can’t forget that we are starting to see how AI can be useful for authorization. In 2024, we launched Policy Companion — our Generative AI tool that lowers the entry point for authoring effective attribute-based access control (ABAC) policies and the ability to interpret existing policy code, to anyone who can read English.

Additionally, for those using Microsoft Copilot, it can now assist in writing policies in Abbreviated Language for Authorization (ALFA).

3. API authorization

It was a big year for API authorization as the number of APIs continues to grow, along with the amount of data and functionality they provide. Additionally, the 2023 OWASP Top 10 API Security List highlighted that the top two items are related to access control, emphasizing the importance of securing APIs. And a new Top Ten (General) List is due next year.

We participated in sessions at both Nordic API Summits in Austin and Sweden, where we discussed how to add security through the use of an API gateway, authentication through the use of an OAuth Authorization Server, and fine-grained access control through the use of a Policy Decision Point.

Bonus: Events

In 2024, we attended numerous events, including EIC,Identiverse, and both Gartner IAM Summits in London and Texas. These events facilitated great conversations around authorization and provided opportunities for the AuthZEN Working Group to host interoperability sessions and share progress with the broader community. It’s great to see the support from the analyst and conference community. Plus, stay tuned as the group will be running an interop at Gartner IAM in London for 2025.

We also participated in FIDO Alliance’s Authenticate this year. Like authentication, it’s in the name. Right? But they gave our working group some time for presentations and interop at the event. It’s encouraging to see more people recognizing authorization as the next critical step following the maturation of authentication.

The future of authorization in 2025

Looking forward, 2025 will be the year of education and outreach as more people start to think about authorization and we’re here to help!

Furthering standards

We’re excited to continue working with the AuthZEN Working Group this year as we work towards a AuthZEN 1.0 standard by June. The group is also working on comprehensiveness of the authorization APIs, being able to do things like search, which is the equivalent of reverse query and building out more of that interoperability. Plus, we’re looking forward to doing more outreach and growing awareness of the community.

It’s important for organizations to critically evaluate emerging approaches in the identity and access management space. While some methods, such as adding additional claims to access tokens or overloading tokens with more information, may seem like a quick path to finer-grained access control, they often come with hidden challenges. These approaches risk placing an undue burden on the identity layer, limiting scalability, and failing to provide dynamic, real-time, relationship-based authorization.

Organizations should focus on solutions that are purpose-built for robust, adaptable, and comprehensive access control. Ensuring that your authorization strategy evolves to meet these demands will not only enhance security but also enable smoother integration and operational efficiency across your application ecosystem.

We’re also advancing ALFA 2.0, having initiated a working group at IETF, which has garnered significant interest.

Axiomatics on the move

This year, we’ll also release a product offering a seamless end-to-end experience — from gathering authorization requirements to implementation and access reviews. This will enhance the user experience for authorization administrators.

In 2024, we launched Axiomatics Labs, a one-stop shop for all your developer-related needs. The Labs connects our different online properties where developers may find useful resources like GitHub repositories, Postman collections, and more. Labs is the first place to go to explore new prototypes and beta integrations, ask developer-centric questions, and more. This is just the beginning as we continue enhancing the developer experience.

We will also be attending:

We look forward to the insightful sessions and engaging conversations at these events.

What do you think?

What’s on your authorization wish list in the year ahead? Read more on:

Ready to start your authorization journey? Request a demo with one of our solution experts.

Have 30 minutes? Let's show you a demo!

See how our award-winning solution can help you meet today's access control and Zero Trust needs.

Request a demo

  Join us on LinkedIn for more insights
Archived under:
About David Brossard

As Chief Technology Officer, David has experience leading the design and development of Salesforce’s identity offering including customer identity and access management (CIAM). He is a founding member of IDPro, a co-author of the OASIS XACML standard, and an expert on standard-based authorization as part of an overall IAM implementation.