Our State of Authorization: AI Edition is now available Get it now »
pen writing

Axiomatics Blog : Attribute Based Access Control (ABAC)

Stay in the know on the latest in authorization, attribute-based access control (ABAC), and modernizing your access control strategy.



All articles

How authorization fits in the OWASP MCP top 10

Learn the different OWASP MCP risks to practical authorization controls for securing, monitoring, and auditing AI systems.

Read the article

Migrating from Styra DAS to Axiomatics: What enterprises need to know

While OPA enables ABAC through Rego, Axiomatics delivers ABAC as a first-class, centrally governed capability with built-in policy lifecycle management, auditability, and standard-based interoperability.

Read the article

5 regulations in North America and how ABAC helps meet requirements

North American organizations are pressured to keep up with compliance requirements, which increasingly calls for smarter ways to manage access.

Read the article

5 regulations in Europe and how ABAC helps

Learn the five, critical European regulations and how ABAC facilitates compliance through practical examples.

Read the article

How authorization can help limit the risk of role explosion

Role explosion can happen before organizations realize it's a risk. Learn how policy-driven authorization can help.

Read the article

Beyond MFA: Limit the blast radius with ABAC

Learn how a robust authorization strategy can become a powerful deterrent to today’s most sophisticated cyber threats.

Read the article

The authorization alphabet soup: What do all these letters mean?

In the identity and access management space, there are a LOT of acronyms. ABAC, PBAC, RBAC, ReBAC. Learn what they mean and how they're used.

Read the article

Secure your RAG: Where to start?

To minimize the risks with RAG, organizations must implement access control that ensures AI systems operate within secure and controlled parameters.

Read the article

How ABAC can help solve the JML problem

The Joiner, Mover, and Leaver problem is a decades old issue enterprises are still looking to solve. See how attribute-based access control can fix it.

Read the article

5 steps to get started with policy-based authorization

Implementing ABAC can transform how and org handles data. Though it may seem overwhelming at first, implementation is simpler than you think.

Read the article

The haunting disadvantages of isolated authorization: Why policy-driven authorization is a treat

Dive into the disadvantages of isolated authorization and discover how policy-driven authorization can help you avoid the pitfalls of an isolated approach.

Read the article

Axiomatics: Leading the charge in authorization innovation

How we began as a small team of researchers to emerge as an innovator in access control, paving a bold path for the future.

Read the article

AuthZzzz – Why our policy-driven authorization should help you sleep at night

How our customers rest easy knowing that our solution and deployment strategy delivers - no matter how complex their environment

Read the article

The best and simplest way to explain authorization

CPO Mark Cassetta shows how authorization takes a fine-grained approach to access control where authentication alone cannot.

Read the article

It’s time to take a holistic approach to cybersecurity by rethinking policies

Solving cybersecurity threats shouldn’t be seen as discrete. Rather it is important to take a holistic approach to achieve the overall result of cybersecurity.

Read the article

Q&A: Auditing and Authorization

David Brossard and Matt Luckett discuss how policy-driven authorization can help improve auditing.

Read the article

Handling multi-valued attributes in ALFA – How “bag” can it get?

See how you can leverage the power of ALFA to help your Policy Decision Point (PDP) handle multi-valued attributes.

Read the article

The future of work, or work today, requires access control

As the world shifts to being remote there is an importance placed on collaboration. This shift requires access control to make the experience frictionless.

Read the article

Manual access recertification is tedious and ineffective. So…why do we still ask managers to do this?

A look into the manual recertification process and the extremes companies think to go to to ensure the process is done correctly.

Read the article

Q&A: Critical infrastructure and policy-driven authorization with Mark Cassetta

Mark Cassetta discusses how policy-driven authorization reduces cyber risks that critical infrastructure organizations face in a modern world.

Read the article

What can the travel industry do to prevent another Southwest outage

The holiday season is one of the busiest travel times each year. As traveling picks up, organizations must prioritize modernizing their cybersecurity strategy.

Read the article

What is cloud-native authorization and why should I care?

Cloud-native software is a priority for enterprises. Learn what the biggest challenge along the cloud-native authorization journey and how to solve it.

Read the article

Playbook drilldown: Deployment methodology

We’ve pulled together a few questions we often ask that identify core priorities for a policy-driven authorization deployment.

Read the article

Playing by the book: Authorization

While enterprises are acknowledging the importance of authorization, there is still a lack of understanding of what authorization really is.

Read the article