Modern Authorization: ABAC, ReBAC, Policy-as-Code
Combined Session
Thursday, May 21, 2026 12:05—13:05
Location: B 07-08
Thursday, May 21, 2026 12:05—13:05
Location: B 07-08
Watch the video
This panel examines how large enterprises can modernize complex, legacy authorization landscapes into clear, business-aligned role models. As entitlement sprawl grows and regulatory pressure increases, getting authorization right is essential for security, compliance and operational efficiency. Panelists will share data-driven techniques for analyzing entitlements, designing meaningful roles and embedding least privilege, segregation of duties and traceability. Attendees will learn practical methods to involve business stakeholders, run simulations and establish ownership, gaining actionable guidance for governing large-scale authorization models in regulated environments.
Watch the video
Delegated authorization is emerging as a foundational capability for enabling trusted digital relationships—whether between people, organizations, or intelligent agents. At its core, it’s not just about “delegation” but about defining, expressing, and enabling authorization within the context of a relationship. From guardianship and customer care to enterprise workflows and Agentic AI, delegated authorization unlocks the ability to act on behalf of others safely, transparently, and with appropriate consent.
This talk explores how relationship-based authorization is evolving across industries and standards communities. We’ll examine what’s working, where key gaps remain, and how emerging patterns—such as contextual delegation and relationship-bound credentials—can improve both usability and privacy. As identity ecosystems become more automated and interconnected, robust models for delegated authorization will be essential to maintaining trust and control across all types of relationships.
Watch the video
Authorization feels inseparable from your product, so we keep rebuilding it in every service, framework, and rewrite. In this talk, I’ll challenge that assumption and show how treating authorization as shared infrastructure (without giving up product-specific logic) actually makes systems safer, more flexible, and easier to evolve.
The audience will learn how to assess inefficiencies in their applications and processes, decouple authorization and application logic, and consume authorization as a shared service without compromising their unique security and business needs.