Modern Authorization: ABAC, ReBAC, Policy-as-Code
Combined Session
Friday, May 22, 2026 11:35—12:35
Location: B 07-08
Friday, May 22, 2026 11:35—12:35
Location: B 07-08
Watch the video
Watch the video
Authorization is evolving fast - every week seems to bring a new acronym or model promising smarter, faster, more dynamic access control. But which of these “modern” models actually add value, which replace existing approaches and which simply rename existing concepts?
This session takes a critical look at the evolution of authorization, from classical models like DAC, MAC, and RBAC to today’s more dynamic approaches such as ABAC, PBAC, ReBAC, and TBAC. You’ll learn how each model aims to address key challenges. It'll also be discussed, which three fundamental dimensions every access control model must handle and evaluate which approaches truly meet those requirements.
By the end of this talk, you’ll understand where modern authorization adds real value, where traditional models still suffice, and how to navigate the hybrid future most organizations will face. The shift in authorization isn’t a revolution - it’s an evolution, and success depends on knowing when to adopt what.
Watch the video
API-first architectures and microservices introduce a new class of identities - workloads - whose access needs are dynamic, unpredictable, and impossible to capture with traditional IAM models. When a single request can trigger a chain of service-to-service calls, how do we ensure every step respects the user’s entitlements, without over-privileging the services themselves?
In this session, Reiner Mertens, Lead Advisor at KuppingerCole Analysts, argues that this is not primarily a technology problem. The tools exist - policy engines, token exchange standards, workload identity frameworks. The problem is organizational: IAM programs are not designed for a world where no single team owns the full API graph, where services are built before authorization is designed, and where policy ownership has no clear home.
Participants will leave with a clear understanding of the challenge, a strong advisory perspective on what must change in IAM programs, and an initial reference model for approaching dynamic entitlements in modern service architectures.