Our Speaking Sessions
Beyond Authentication: Updates from the Authorization Frontier
Date: Monday, June 15 at 1:30-2:20pm PST
Authentication is mature, we know who you are. We all resort to standard frameworks for authentication. We use SAML, OAuth, and OpenID Connect for single-sign-on, federation, and overall user management. The question, though, is what can you do? In other words, what about authorization or access control? How do we make sure only the right individuals (or agents or processes) get access to the right circumstances in a transparent, auditable, and accountable way? This is what fine-grained authorization aims to deliver.
This session will provide an overview of today’s authorization landscape, highlighting existing frameworks, patterns, and standards. We will focus on OpenID AuthZEN, its drivers and features. We will finish with a call to arms: require that your SaaS and COTS Providers adopt AuthZEN to eliminate authorization silos.
AuthZEN Deep Dive: Mastering the OpenID Authorization Standard
Date: Monday, June 15 at 2:30-3:20pm PST
You’ve heard the case for externalized authorization, now it’s time to get your hands dirty. This masterclass takes you inside the OpenID AuthZEN specification, equipping you with the knowledge and practical understanding to evaluate, implement, and advocate for AuthZEN in your own organization.
We begin with the specification itself: unpacking the core API surface, the access evaluation request and response model, and the subject, resource, and action primitives that make AuthZEN expressive yet interoperable. We’ll walk through real API calls, what a well-formed access evaluation request looks like, how a compliant PDP responds, and how to handle batch evaluations and context-rich decisions at runtime.
Attendees will leave with:
- A working understanding of the AuthZEN spec – the API, the data model, and the design decisions behind them.
- Lessons from interoperability – what real-world testing has taught the community about building conformant, robust implementations.
- A blueprint for AI-era authorization – how to extend your AuthZEN deployment to govern agentic and MCP-based workloads today.