Authorization is evolving fast - every week seems to bring a new acronym or model promising smarter, faster, more dynamic access control. But which of these “modern” models actually add value, which replace existing approaches and which simply rename existing concepts?
This session takes a critical look at the evolution of authorization, from classical models like DAC, MAC, and RBAC to today’s more dynamic approaches such as ABAC, PBAC, ReBAC, and TBAC. You’ll learn how each model aims to address key challenges. It'll also be discussed, which three fundamental dimensions every access control model must handle and evaluate which approaches truly meet those requirements.
By the end of this talk, you’ll understand where modern authorization adds real value, where traditional models still suffice, and how to navigate the hybrid future most organizations will face. The shift in authorization isn’t a revolution - it’s an evolution, and success depends on knowing when to adopt what.