Migrating from Styra DAS to Axiomatics: What enterprises need to know
While OPA enables ABAC through Rego, Axiomatics delivers ABAC as a first-class, centrally governed capability with built-in policy lifecycle management, auditability, and standard-based interoperability.
Open Policy Agent (OPA) remains a powerful and widely adopted policy engine. Many teams will continue using it successfully. However, organizations that relied on Styra for enterprise support, policy lifecycle tooling, and governance now face a strategic decision to consider alternatives. Axiomatics is a proven, enterprise-ready authorization platform that delivers attribute-based access control (ABAC) for applications, data, APIs, and microservices — ensuring secure, scalable, and future-proof access management.
Axiomatics: Your enterprise ready alternative for Styra
For teams evaluating their options in light of Styra’s enterprise offerings being sunset, Axiomatics provides an alternative for application authorization, infrastructure guardrails, and data access control. While OPA enables ABAC through Rego, Axiomatics delivers ABAC as a first-class, centrally governed capability with built-in policy lifecycle management, auditability, and standard-based interoperability.
This makes Axiomatics well-suited for enterprises that need to centrally manage and enforce fine-grained, policy-driven access across complex environments. By enabling real-time, context-aware authorization decisions, Axiomatics helps organizations ensure that only the right users access the right resources under the right conditions.
| Features | Styra DAS | Axiomatics |
|---|---|---|
| Policy Authoring |
|
|
| Policy Impact Analysis |
|
|
| Distribution |
|
|
| Monitoring and Logging |
|
|
| Enterprise Readiness | Yes | Yes |
Axiomatics has designed its solution for enterprise-wide deployments at scale. The engines are built to deliver highly scalable and available authorization capabilities. The authorization APIs cover both binary access control (Can Alice view record #123?), batch access control, and open-ended access control for listing, and data filtering.
Axiomatics’ control plane is designed with a cloud-native, microservices-based architecture that allows it to scale to a large number of teams that can collaborate together or work independently side by side. The key features allow for managers to collaborate on different projects. The API-first approach lets developers use their preferred tooling (IDE) and integrate with their continuous integration and continuous delivery (CI/CD) pipelines.
Abbreviated Language of Authorization (ALFA) is a constrained language, it is easy to test, audit, and run access reviews on the policies providing compliance managers with the assurance that the authorization configuration is delivering on the requirements.
What changes, what improves?
When moving to Axiomatics from Styra DAS you might wonder what are the differences between the platforms. The first thought that might come to mind is, does the architecture change? No, it doesn’t. Both Styra DAS which builds on top of OPA and Axiomatics use the same architectural approach whereby a Policy Enforcement Point (PEP) protects a resource and sends an authorization request to a Policy Decision Point. This is in line with NIST ABAC 800-162 and NIST Zero Trust 800-207.
As the architecture doesn’t change neither does the approach. Both Styra DAS and Axiomatics are policy-as-code approaches so developers can write their authorization configuration through policies.
However, the policy language is different between the two. While Styra DAS uses OPA’s Rego, Axiomatics uses ALFA. OPA is a full-blown programming language based on Datalog which makes it both very capable and somewhat harder to learn. ALFA is a constrained, purpose-built, and stateless declarative language meant for authorization. ALFA is in fact easier to read and write than Rego.
It’s even possible to enforce decisions in your own language (Python, Ruby, Typescript, Java, .NET, etc.) because both OPA and the Axiomatics Authorization engine expose a REST/JSON interface. This is straightforward to send a request to the engines, process, and enforce the decision it receives back.
Some other questions around the differences may include:
- Can I still use any attribute data source? Yes, both Styra and Axiomatics allow policies to use data stored in third-party services. Axiomatics provides native support for so-called “Policy Information Points” (PIPs).
- Can I express role-based access control (RBAC) use cases? Yes, both Styra DAS and Axiomatics can be used to easily express policies that use roles and role hierarchies.
- Can I express dynamic, context-based access control? Yes, this is a key benefit of policy-as-code approaches: both Styra DAS and Axiomatics can use context, time of day, location, and risk as attributes in their policies. Axiomatics provides a rich dictionary through which attributes can be defined and reasoned on.
- Can I express relationship-based access control (ReBAC)? Yes, both Styra policies and Axiomatics policies (Rego and ALFA respectively) can be used to express access control based on relationships (either direct e.g. parent-child or indirect e.g. a user getting access to a resource in the same department).
- Can I use an Open Policy Agent PEP with an Axiomatics PDP? Yes, with the advent of OpenID AuthZEN, the community is collectively building interoperability between enforcement and decision points.
- Does the Axiomatics engine perform as well as the Styra engine? Yes, both engines are capable of sub-millisecond latency decision making.
If there’s any other questions you have around the differences between Styra DAS and Axiomatics, feel free to reach out to our solution experts and we’re happy to help answer them.
Schedule a Rego policy review with our policy experts
Review your architecture and configuration with our architects and set a path forward.
FAQ
Did Apple acquire Styra?
No, however, they did “acqui-hire” the founding team and key engineers behind Styra and its Open Policy Agent (OPA) project according to the official announcement on the OPA blog.
What happens to existing OPA deployments?
OPA continues to be an open-source project governed by the CNCF and will continue functioning. However, Styra’s enterprise offerings (like DAS) will no longer be actively developed in the same way. The community may maintain them, but organizations should not expect the same commercial roadmap or enterprise-level support.
Due to the enterprise offerings being sunset, organizations using Styra’s commercial products should evaluate alternatives for enterprise support and advanced features.
Can Axiomatics handle the complex authorization patterns of OPA?
Yes, Axiomatics can handle complex authorization patterns. The Axiomatics Authorization Management Platform uses ALFA as a policy language rather than OPA’s Rego. ALFA is a more constrained language making it easier to read, write and test policies. Additionally, everything that is expressed in ALFA can be translated to Rego.
How do I avoid vendor lock-in?
From its inception, Axiomatics has always been standards-first. It started with eXtensible Access Control Markup Language (XACML) where one of Axiomatics’ co-founders was the editor for the standard. It carries on today with the Abbreviated Language for Authorization (ALFA), and OpenID AuthZEN which we are spearheading as one of the co-chairs. Building and innovating on top of standards is in our DNA to deliver the best possible customer experience.
How does Axiomatics ensure long-term stability?
Axiomatics has been operating for nearly two decades and supporting numerous enterprise customers around the world. Today, most of our customers are Global Fortune 1,000 companies. Lastly, Axiomatics is a fully-owned subsidiary of Leonardo, a global leader in cybersecurity and Zero Trust.
Have 30 minutes? Let's show you a demo!
See how our award-winning solution can help you meet today's access control and Zero Trust needs.
Request a demoJoin us on LinkedIn for more insights
