Leadership Compass

This is an update of our 2024 report on Policy Based Access Management. If you would like to see what this report entails, you can view it by clicking this link.

This Leadership Compass evaluates various solutions, covering a range of use cases and capabilities like Policy-Based Access Management (PBAM) and JIT privileged access, and offers insights into whether solutions provide broad functionality or specialize deeply, guiding readers to choose options that best fit their needs.

Inclusion Criteria

We look at all solutions that support PBAM and at minimum either policy administration and policy governance or policy decision and enforcements. Solutions can be focused on specific use cases.

  • Solutions should provide a consistent model for decision point, enforcement points (relying on applications etc.) and distributed policy management points
  • Solutions should perform authorization decisions at runtime for various and distributed systems
  • Solutions should provide policy lifecycle management for creating, testing, managing, implementing, updating, and retiring policies.
  • Solutions should support externalized and internalized authorization services.
  • Solutions should adhere to standards such as XACML, OPA, Rego, OpenFGA for defining policies in a consistent manner and integration with applications and systems

Exclusion Criteria

We exclude solutions that don’t support PBAM approaches which are not basing decisions on defined and centrally managed policies.

  • Solutions that support policy-based authorization decisions only for proprietary instances
  • Solutions that are limited to RBAC support
  • Solutions that have limited deployments e.g. start-ups, proof-of-concept only
  • Solutions that do not have active customers yet

However, there are no further exclusion criteria such as revenue or number of customers. We cover vendors from all regions, from start-ups to large companies.

How to Book a Briefing
  1. Go to the KuppingerCole Booking tool webpage.
  2. Under Select a Service, select Leadership Compass Briefing 45 mins.
  3. Under Select Staff, scroll down and select Nitish Deshpande
  4. Choose date and time between March 10 – April 4, 2025 that are convenient for your team. Please note: Times will be shown in your time zone.
  5. You will receive an MS Teams invite that you can forward along to others in your company. Alternatively, you can use this as a placeholder and send us an invite with another app.
  6. Please prepare a slide deck and provide it to the analyst

Briefing Outline for LC Policy Based Access Management:

The briefing should give an overview presentation of these key topic areas, as well as a demo of the product capabilities:

  • Short Company Overview (facts & figures, partner ecosystem, etc.)
  • Product Overview
    • Key capabilities
    • Major updates you’ve made to your product over the past 6 months
    • Policy administration, creation, and management options
    • Policy enforcement, integration with relying parties
    • Policy decision points deployment options
    • Policy information point integration options
    • Support for standards (REGO, ALFA, AuthZen, OPA, XACML etc.)
    • Support for frameworks/languages provided by AWS (such as Cedar) and Google GCP (Zanzibar)
    • Policy governance e.g., policy analytics, audit, forensic, compliance and reporting
    • Overview about supported deployment models and as-a-Service/MSP offerings
    • Software architecture in detail, with specific respect to microservices, their granularity, and the flexibility in deployment (e.g. whether customers can change packaging of microservices in containers and whether they can control where which containers reside)
  • Roadmap
    • Major updates you have in the roadmap for the next 6 to 12 months
  • Competitive Positioning (USP)
  • Licensing models, specifically with respect to “pay per use” / elasticity
  • Short demo (max. 10-15 minutes) covering the following areas
    • Administrative user interface
    • Dashboards and reporting
    • Features that are being perceived by the vendor as being unique / distinguishing from the competition

The demo can be live or recorded. If you have more material to show than time allows, please feel free to record extended demos and send links. Analysts find this approach useful for reviewing later.

Please prepare a slide deck and send it to us before the call.

Your Benefits of Participation

Benefit from Third-Party Attestation

Receive an objective evaluation of your solution that you can easily integrate into your marketing strategy. Our vendor neutral approach ensures results are trustworthy and credible. Use this assessment as a powerful marketing asset to enhance customer trust.

Increase Brand Awareness

Share your cybersecurity expertise with the world. By participating in our analysis, you gain a platform to spotlight your company. Boost your visibility and establish yourself as a leading provider in the industry. If you take part in this Leadership Compass, your solution will be featured in our Research Library at no cost to you.

Get Insights Into Competing Solutions

Discover how your solution compares with others in the industry. Our analysis provides insights not only into your solution but also valuable information about competitors. Utilize this knowledge to strengthen your position in the market.

Gain Valuable Insights on Your Market Standing

Benefit from a thorough, complimentary evaluation of your solution. KuppingerCole Analysts will evaluate not only your product but also your positioning in the market. Seize this opportunity to receive valuable feedback and make your solution even more effective.

Switch to dark theme

Research Assistant

Hi, I'm Kuppi, your AI-powered research assistant. Ask me about KuppingerCole Analysts' research, events, or analysts.
As an AI assistant, I can make mistakes. Please verify important information.