Digital transformation increases exposure of “crown jewels,” yet many breaches stem less from sophisticated attacks than from weak, inconsistent authorization. While authentication has advanced from passwords to biometrics, MFA, and risk-based methods, authorization frequently remains fragmented: handled per application, owned by IT teams rather than management, and misaligned with business processes. As infrastructures become hybrid and heterogeneous (on‑prem, cloud, SaaS, mobile), the absence of shared security models forces organizations to define policies repeatedly, usually falling back on coarse-grained RBAC. Even when enterprise security policies exist in business language, translating them into technical controls is difficult, despite standards like XACML and OAuth 2.0.
PlainID, a privately held authorization vendor founded in 2014 and headquartered in Tel Aviv, addresses this gap with Policy-Based Access Control (PBAC), unifying static roles with dynamic attributes of users, devices, and resources to enable real-time, fine-grained decisions. The platform centralizes business-oriented policy design in a graphical console, hiding technical complexity while supporting workflows, approvals, segregation of duties, sandboxes for testing, and version control. A server component (“Rule Engine”) combines GUI, lifecycle management, runtime decisioning, and integration interfaces, storing authorization artifacts in an embedded graph database and supporting clustering and separate test/stage deployments.
PlainID integrates with standards (XACML, OAuth 2.0, token formats) and third-party systems (IAM/IGA, database proxies, Hadoop, SaaS). Recognizing legacy constraints, it expanded in 2019 to cover coarse to fine-grained authorization in one platform, adding Role & Entitlement Manager (lifecycle management plus analytics, mining, forensics) and Partner Manager for B2B delegated administration with global policies and auditing. Strengths include unified authorization coverage and business-friendly tooling; challenges include no built-in enforcement and prior niche positioning.
See All Locations
See All Locations