Aserto built a fine-grained authorization platform around Topaz, an Apache 2.0 authorizer that pairs Open Policy Agent (Rego) with a Zanzibar-style relationship directory. The hosted Aserto Control Plane shut down on 31 May 2025; Topaz continues as a self-hosted open-source project.
Authorization
Fine-grained authorization and policy engines — what identities are allowed to do.
11 vendors ·
Quick answer
What is Authorization?
Short answer
Authorization platforms decide what an already-authenticated identity — human, workload, or AI agent — is allowed to do. They externalize RBAC, ABAC, PBAC, and ReBAC policy from application code into policy engines that are testable, auditable, and consistently enforced across services, APIs, and infrastructure.
- Best for
- Engineering and platform teams whose permission logic has outgrown hard-coded role checks, or who need consistent access decisions across many services, gateways, data platforms, and AI agents.
- When to choose
- Compare policy language ergonomics, supported models (RBAC/ABAC/PBAC/ReBAC), decision latency, data enrichment at decision time, audit logging, and self-hosted vs managed control planes.
- When not to choose
- Skip Authorization tooling if a broader IAM platform already covers your needs and you don't have category-specific requirements.
Request a vendor shortlist
Tell us what you're evaluating and IDSync will identify the identity, access, and security tools that fit your use case.
Top vendors in Authorization
Maker of SpiceDB, the Apache-2.0 "open source permissions database" inspired by Google Zanzibar, offered self-hosted, as usage-priced AuthZed Cloud, as Dedicated cloud, or as a licensed self-hosted enterprise build.
Casbin is an Apache 2.0 open-source authorization library, embedded in-process, that evaluates ACL, RBAC, ABAC and other models defined in a model.conf file against policy rules loaded from CSV or a database adapter. It entered the Apache Incubator in February 2026.
Cerbos is an authorization management platform built around an open source policy decision point (PDP). It enforces fine-grained RBAC, ABAC, PBAC, and ReBAC policies for applications, APIs, workloads, and AI agents.
Keycard is an identity and access platform purpose-built for AI agents, founded by former Snyk and Auth0 leaders (including the creator of Passport.js). It verifies agent identity, mints short-lived task-scoped tokens in place of static API keys, and enforces runtime policy with auditable logs.
Open Policy Agent is an Apache 2.0, CNCF Graduated policy engine that evaluates Rego policies for application authorization, Kubernetes admission (Gatekeeper), Envoy/Istio, Terraform and CI/CD. It returns decisions; your services enforce them.
OpenFGA is an Apache 2.0 authorization engine, inspired by Google's Zanzibar paper, that stores relationship tuples and answers permission checks via gRPC/HTTP APIs. Originally built by Auth0/Okta, it is now a CNCF Incubating project with a hosted Auth0 FGA option.
Oso Cloud is a managed authorization service where teams model RBAC, ReBAC and ABAC in the Polar language and query it from Node.js, Python, Go, Java, Ruby or .NET SDKs. In 2026 Oso added Oso for Agents, a control product for AI coding agents.
P0 Security provides an authorization control plane that discovers users, service accounts, agents, and MCP servers with sensitive access, then enforces just-in-time, short-lived access and centralized policy governance across cloud providers, Kubernetes, databases, and servers. It positions itself as a cloud-native alternative to traditional PAM.
Permit.io provides authorization-as-a-service with a low-code policy management interface, RBAC/ABAC/ReBAC policy support, and a managed policy decision layer — enabling teams to ship fine-grained access control without building it from scratch.
Enterprise policy-based access control (PBAC) platform that centralises authorization policies and enforces them at runtime across APIs, data platforms, applications and AI agents.
Related categories
Pick the right Authorization tool
Tell us about your stack and we'll send a tailored vendor shortlist for Authorization.
Request vendor shortlist →Run Stack FinderSponsor Authorization
Get featured placement at the top of this category and its comparisons.
