IT environments have grown more complex as enterprises expose more digital services via APIs and must enforce appropriate, authorized access that meets regulatory expectations. Traditional authorization, often embedded in individual applications with local entitlement stores, makes it hard to manage and enforce consistent enterprise-wide policies. Dynamic contextual authorization addresses this by using richer context to enable fine-grained, centrally managed controls over protected resources, supporting needs such as GDPR-oriented data authorization and Open Banking/PSD2 scenarios where banks must securely expose APIs to third parties while reducing fraud risk.
Modern security requirements also extend to mobile apps, IoT, machine-to-machine communication, and edge gateways, alongside a shift toward microservices and containerized architectures. While microservices enable autonomous teams and diverse technology stacks, they can create inconsistent authorization implementations (for example, divergent interpretations of token scope values). As expectations rise, authorization solutions are expected to support automation, incorporate AI-driven analytics for risk and suspicious event detection, and offer more intuitive policy authoring than traditionally complex policy languages.
Cloudentity, a Seattle-based privately held IAM vendor, positions its cloud-native CIAM.next platform (introduced in 2017) around dynamic authorization and authorization-as-code for APIs, microservices, and traditional workloads. Its Authorization Control Plane (ACP) sits between identity providers and application security, using identity session tokens plus contextual patterns to refresh and augment session data across security services. A key component, the Identity Hub, normalizes inconsistent OpenID Connect profile attributes across IdPs (e.g., “email” vs. “email-address”) and can ingest large-scale third-party data sources. ACP automates API discovery through integrations with gateways and service mesh sidecars and uses an open-source PDP (Pyron) plus distributed authorizers to enforce policy. Cloudentity provides a near-natural-language policy engine built on OPA, drag-and-drop authoring, policy packs, real-time testing, and bundled BI/analytics, with flexible SaaS and on-premises deployment options.
See All Locations
See All Locations