Our State of Authorization: AI Edition is now available Get it now »

Articles by David Brossard

As Chief Technology Officer, David has experience leading the design and development of Salesforce’s identity offering including customer identity and access management (CIAM). He is a founding member of IDPro, a co-author of the OASIS XACML standard, and an expert on standard-based authorization as part of an overall IAM implementation.


All articles
Access Control

The Challenge Isn’t AI. The Challenge Is Authorization.

While these look like AI-specific challenges, they reflect a long-standing enterprise issue: authorization.

Read the article
Access Control

How policy-driven authorization can alleviate authorization debt

The pace at which authorization debt grows is increasing exponentially. Policy-driven authorization can help address the risks.

Read the article
Company Updates

5 sessions to attend at the Gartner IAM Summit 2026 in London

Our team is heading to London for the Gartner Identity and Access Management (IAM) Summit being held on March 9 and 10, 2026.

Read the article
Access Control

Migrating from Styra DAS to Axiomatics: What enterprises need to know

While OPA enables ABAC through Rego, Axiomatics delivers ABAC as a first-class, centrally governed capability with built-in policy lifecycle management, auditability, and standard-based interoperability.

Read the article
Zero Trust

The critical role of the Policy Engine in Zero Trust architecture

Dive into Zero Trust architecture principles, focusing on data protection and rigorous authentication to enhance security.

Read the article
Access Control

Enforcement Strategies: When PEPs are not enough

At the heart of modern authorization is the PEP/PDP architecture. But what if the target application doesn’t support PEP integration?

Read the article
Access Control

Agentic AI and NHIs: Why authorization is a must-have

Non-human identities are rapidly evolving, Agentic AI being at top of mind. Authorization methods, like Zero Trust, are impartive now more than ever.

Read the article
Attribute Based Access Control (ABAC)

The authorization alphabet soup: What do all these letters mean?

In the identity and access management space, there are a LOT of acronyms. ABAC, PBAC, RBAC, ReBAC. Learn what they mean and how they're used.

Read the article
Policy-driven Authorization

Alleviating IAM technical debt through policy-driven authorization

Technical debt can severely hinder the agility of an IAM team. See how policy-driven authorization can help mitigate IAM technical debt.

Read the article
OpenID AuthZEN

Introducing the era of authorization with AuthZEN

Learn about the standards the AuthZEN Working Group is setting for the IAM industry. Also, see where they'll be presenting in early 2025.

Read the article
Access Control

10 rules to successful policy authoring

Learn the ten key rules to successful policy authoring when implementing authorization policies to meet your organizational needs.

Read the article
Access Control

The 10 biggest issues CISOs face today and how authorization can help

We look at 10 issues that are top-of-mind for CISOs and see how policy-driven authorization can help solve these issues.

Read the article
Access Control

2024 wrapped and looking ahead to 2025

We recap the highlights of 2024 in authorization and look ahead to what we have planned throughout 2025.

Read the article
Access Control

ABAC to the future: The next generation of access control

Authorization has shifted from gatekeeping to empowering the right people to access the right data at the right time. Enter ABAC...

Read the article
Relationship-based Access Control (ReBAC)

Demystifying relationship-based access control (ReBAC): what you need to know

ReBAC can be a nebulous term, leading to confusion and varied interpretations. What is ReBAC? Is it better than attribute-based access control (ABAC)?

Read the article
Access Control

Policies or graphs: which approach works best?

Learn about the main models of authorization and how to choose the approach that best fits your access control landscape.

Read the article
Access Control

It’s time to take a holistic approach to cybersecurity by rethinking policies

Solving cybersecurity threats shouldn’t be seen as discrete. Rather it is important to take a holistic approach to achieve the overall result of cybersecurity.

Read the article
Access Control

Five things developers need to know about APIs and authorization

It's becoming increasingly difficult to understand what APIs are exposed and how. Learn why policy-driven authorization can elevate your API security.

Read the article
Access Control

OAuth and Authorization: A duo in securing access to API-based services

Learn how OAuth specification plays an important role in API-centric access and authentication.

Read the article
Attribute Based Access Control (ABAC)

Handling multi-valued attributes in ALFA – How “bag” can it get?

See how you can leverage the power of ALFA to help your Policy Decision Point (PDP) handle multi-valued attributes.

Read the article
Policy Languages

Does the JSON profile for XACML support MDP?

Axiomatics also supports the JSON over REST authorization interface on its PDPs, providing XACML support for MDP. Learn how.

Read the article
Policy Languages

What’s the difference between policy target and rule target in ALFA?

Learn how you can use ALFA to specify a Target in both a Policy and a Rule, addressing a common question using XACML.

Read the article
Access Control

Why does an API gateway need authorization?

To understand why an API gateway needs authorization, we must understand what an API gateway is used for to see why authorization is needed.

Read the article
Policy Languages

Ten years of ALFA. Wait…what?

The evolution of access control has significantly changed. With more than a decade of ALFA, let’s take a look back at its history.

Read the article