<rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Hacker News: ogazitt</title><link>https://news.ycombinator.com/user?id=ogazitt</link><description>Hacker News RSS</description><docs>https://hnrss.org/</docs><generator>hnrss v2.1.1</generator><lastBuildDate>Sat, 13 Jun 2026 17:55:11 +0000</lastBuildDate><atom:link href="https://hnrss.org/user?id=ogazitt" rel="self" type="application/rss+xml"></atom:link><item><title><![CDATA[Building permission-aware AI chatbots]]></title><description><![CDATA[
<p>Article URL: <a href="https://www.aserto.com/blog/building-permission-aware-enterprise-chatbots">https://www.aserto.com/blog/building-permission-aware-enterprise-chatbots</a></p>
<p>Comments URL: <a href="https://news.ycombinator.com/item?id=42077828">https://news.ycombinator.com/item?id=42077828</a></p>
<p>Points: 1</p>
<p># Comments: 0</p>
]]></description><pubDate>Thu, 07 Nov 2024 16:03:11 +0000</pubDate><link>https://www.aserto.com/blog/building-permission-aware-enterprise-chatbots</link><dc:creator>ogazitt</dc:creator><comments>https://news.ycombinator.com/item?id=42077828</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=42077828</guid></item><item><title><![CDATA[RAG with Access Control]]></title><description><![CDATA[
<p>Article URL: <a href="https://www.pinecone.io/learn/rag-access-control/">https://www.pinecone.io/learn/rag-access-control/</a></p>
<p>Comments URL: <a href="https://news.ycombinator.com/item?id=40159306">https://news.ycombinator.com/item?id=40159306</a></p>
<p>Points: 3</p>
<p># Comments: 2</p>
]]></description><pubDate>Thu, 25 Apr 2024 16:09:36 +0000</pubDate><link>https://www.pinecone.io/learn/rag-access-control/</link><dc:creator>ogazitt</dc:creator><comments>https://news.ycombinator.com/item?id=40159306</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=40159306</guid></item><item><title><![CDATA[New comment by ogazitt in "Distributed Authorization"]]></title><description><![CDATA[
<p>Congrats on the launch!<p>[Disclosure: I'm one of the co-founders of Aserto, the creators of Topaz].<p>The problem of data filtering is indeed a huge part of building an effective authorization system. Partial evaluation is one way of doing it, although with systems like OPA [0] it requires a lot of heavy lifting (parsing the returned AST and converting it into a WHERE clause). Looking forward to seeing how turnkey that can be with Oso.<p>With that said, there are applications where you really want the data close to the authorization engine. With a ReBAC model, you can easily find the objects that a user has access to, or the users that have access to an object, by walking the relationship graph. That's the approach we've taken with Topaz [1].<p>Funny timing - a few days ago we published a blog post on that very topic! [2]<p>[0] <a href="https://openpolicyagent.org" rel="nofollow">https://openpolicyagent.org</a><p>[1] <a href="https://topaz.sh" rel="nofollow">https://topaz.sh</a><p>[2] <a href="https://www.aserto.com/blog/how-rebac-helps-solve-data-filtering" rel="nofollow">https://www.aserto.com/blog/how-rebac-helps-solve-data-filte...</a></p>
]]></description><pubDate>Wed, 17 Apr 2024 05:33:03 +0000</pubDate><link>https://news.ycombinator.com/item?id=40060834</link><dc:creator>ogazitt</dc:creator><comments>https://news.ycombinator.com/item?id=40060834</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=40060834</guid></item><item><title><![CDATA[New comment by ogazitt in "Open Policy Agent"]]></title><description><![CDATA[
<p>If you want to try Topaz (which supports all three), check it out here [0]. We'd love to help you solve your authorization scenario :)<p>[0] <a href="https://github.com/aserto-dev/topaz">https://github.com/aserto-dev/topaz</a></p>
]]></description><pubDate>Wed, 13 Mar 2024 18:54:35 +0000</pubDate><link>https://news.ycombinator.com/item?id=39695788</link><dc:creator>ogazitt</dc:creator><comments>https://news.ycombinator.com/item?id=39695788</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=39695788</guid></item><item><title><![CDATA[New comment by ogazitt in "Open Policy Agent"]]></title><description><![CDATA[
<p>Topaz is essentially a combination of OPA (which is used as the decision engine, with full support for Rego), and a Zanzibar-style directory, which is fairly isomorphic to what OpenFGA has implemented.<p>The advantage is that it's a single container image (or go binary, if that's how you want to run it), and supports a combination of RBAC, ABAC, and ReBAC. ABAC is accomplished via the Rego language, which is as "standard" as it comes in the cloud-native world.</p>
]]></description><pubDate>Wed, 13 Mar 2024 18:52:59 +0000</pubDate><link>https://news.ycombinator.com/item?id=39695766</link><dc:creator>ogazitt</dc:creator><comments>https://news.ycombinator.com/item?id=39695766</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=39695766</guid></item><item><title><![CDATA[New comment by ogazitt in "Open Policy Agent"]]></title><description><![CDATA[
<p>OPA is a great tool for implementing a policy-as-code system. But if you're trying to use it for application authorization (e.g. fine-grained authz for B2B SaaS or a set of internal applications), you may find that its policy story is strong, but it doesn't really have a "data plane": you either store data in a data.json file and rebuild the policy any time that data changes, or make an http.send call out of the policy to fetch dynamic data.<p>Check out Topaz [0], which uses OPA as its decision engine, but adds a data plane that is based on the ReBAC ideas explored in the Google Zanzibar [1] paper.<p>Disclaimer: I work on the team [2] that builds and maintains the Topaz project.<p>[0] <a href="https://www.topaz.sh" rel="nofollow">https://www.topaz.sh</a><p>[1] <a href="https://research.google/pubs/zanzibar-googles-consistent-global-authorization-system" rel="nofollow">https://research.google/pubs/zanzibar-googles-consistent-glo...</a><p>[2] <a href="https://www.aserto.com" rel="nofollow">https://www.aserto.com</a></p>
]]></description><pubDate>Tue, 12 Mar 2024 22:30:48 +0000</pubDate><link>https://news.ycombinator.com/item?id=39685725</link><dc:creator>ogazitt</dc:creator><comments>https://news.ycombinator.com/item?id=39685725</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=39685725</guid></item><item><title><![CDATA[New comment by ogazitt in "LetsGo – A new starter kit for starting startups"]]></title><description><![CDATA[
<p>LetsGo looks really cool! Excited to see how this evolves.</p>
]]></description><pubDate>Wed, 22 Nov 2023 19:21:50 +0000</pubDate><link>https://news.ycombinator.com/item?id=38383828</link><dc:creator>ogazitt</dc:creator><comments>https://news.ycombinator.com/item?id=38383828</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=38383828</guid></item><item><title><![CDATA[New comment by ogazitt in "Show HN: Add auth to Next.js and deploy in 60 seconds – no manual config"]]></title><description><![CDATA[
<p>Really cool to see an identity provider that's free, both in price and in friction. Nicely done!</p>
]]></description><pubDate>Thu, 16 Nov 2023 02:24:28 +0000</pubDate><link>https://news.ycombinator.com/item?id=38285204</link><dc:creator>ogazitt</dc:creator><comments>https://news.ycombinator.com/item?id=38285204</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=38285204</guid></item><item><title><![CDATA[New comment by ogazitt in "Show HN: Topaz 0.30 – OSS authz service combining the best of OPA and Zanzibar"]]></title><description><![CDATA[
<p>Thanks! Yes, the days where you have to hand-roll authorization logic are (hopefully) soon to be behind us :)</p>
]]></description><pubDate>Mon, 06 Nov 2023 18:53:03 +0000</pubDate><link>https://news.ycombinator.com/item?id=38166996</link><dc:creator>ogazitt</dc:creator><comments>https://news.ycombinator.com/item?id=38166996</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=38166996</guid></item><item><title><![CDATA[New comment by ogazitt in "Show HN: Topaz 0.30 – OSS authz service combining the best of OPA and Zanzibar"]]></title><description><![CDATA[
<p>Thanks! That's exactly the analogy we think of... Auth0 : AuthN :: Topaz : AuthZ :)</p>
]]></description><pubDate>Mon, 06 Nov 2023 18:15:13 +0000</pubDate><link>https://news.ycombinator.com/item?id=38166375</link><dc:creator>ogazitt</dc:creator><comments>https://news.ycombinator.com/item?id=38166375</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=38166375</guid></item><item><title><![CDATA[New comment by ogazitt in "Show HN: Topaz 0.30 – OSS authz service combining the best of OPA and Zanzibar"]]></title><description><![CDATA[
<p>Thanks! Do let us know what your favorite feature is in the 0.30 release :)</p>
]]></description><pubDate>Mon, 06 Nov 2023 16:55:05 +0000</pubDate><link>https://news.ycombinator.com/item?id=38165085</link><dc:creator>ogazitt</dc:creator><comments>https://news.ycombinator.com/item?id=38165085</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=38165085</guid></item><item><title><![CDATA[New comment by ogazitt in "Show HN: Topaz 0.30 – OSS authz service combining the best of OPA and Zanzibar"]]></title><description><![CDATA[
<p>Thanks! ABAC and ReBAC are indeed complementary, and you can build powerful authorization models by combining the best of these.</p>
]]></description><pubDate>Mon, 06 Nov 2023 16:53:20 +0000</pubDate><link>https://news.ycombinator.com/item?id=38165059</link><dc:creator>ogazitt</dc:creator><comments>https://news.ycombinator.com/item?id=38165059</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=38165059</guid></item><item><title><![CDATA[New comment by ogazitt in "Show HN: Topaz 0.30 – OSS authz service combining the best of OPA and Zanzibar"]]></title><description><![CDATA[
<p>Thanks! "topaz test" is already pretty useful, and we hope to bring assertions into the visual console in a future release.</p>
]]></description><pubDate>Mon, 06 Nov 2023 16:52:09 +0000</pubDate><link>https://news.ycombinator.com/item?id=38165046</link><dc:creator>ogazitt</dc:creator><comments>https://news.ycombinator.com/item?id=38165046</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=38165046</guid></item><item><title><![CDATA[New comment by ogazitt in "Show HN: Topaz 0.30 – OSS authz service combining the best of OPA and Zanzibar"]]></title><description><![CDATA[
<p>Thanks for the question! Those are both great projects.  Topaz combines the best elements of both:<p>* It uses OPA as its decision engine and Rego as the policy language, and supports  the "policy as code" methodology<p>* It also implements a ReBAC directory, much like OpenFGA, in the same container image.  It goes further, by allowing you to store not just relationships between subjects and objects, but also properties... which makes it easy to author policies that combine attribute-based (ABAC) and relationship-based (ReBAC) rules.</p>
]]></description><pubDate>Mon, 06 Nov 2023 16:20:55 +0000</pubDate><link>https://news.ycombinator.com/item?id=38164597</link><dc:creator>ogazitt</dc:creator><comments>https://news.ycombinator.com/item?id=38164597</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=38164597</guid></item><item><title><![CDATA[Show HN: Topaz 0.30 – OSS authz service combining the best of OPA and Zanzibar]]></title><description><![CDATA[
<p>Hey folks! As Topaz turns a year old, we just released a big update, including support for a new authorization schema language, a built-in visual console, REST APIs for the ReBAC directory, a full test harness, and many other improvements.<p>Would love to get your feedback! Check out the blog post [0] for the complete details (including some cool screenshots), or clone / fork the repo here [1]. Many thanks!<p>[0] <a href="https://www.aserto.com/blog/announcing-topaz-030" rel="nofollow noreferrer">https://www.aserto.com/blog/announcing-topaz-030</a><p>[1] <a href="https://github.com/aserto-dev/topaz">https://github.com/aserto-dev/topaz</a></p>
<hr>
<p>Comments URL: <a href="https://news.ycombinator.com/item?id=38164327">https://news.ycombinator.com/item?id=38164327</a></p>
<p>Points: 35</p>
<p># Comments: 16</p>
]]></description><pubDate>Mon, 06 Nov 2023 16:02:00 +0000</pubDate><link>https://www.aserto.com/blog/announcing-topaz-030</link><dc:creator>ogazitt</dc:creator><comments>https://news.ycombinator.com/item?id=38164327</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=38164327</guid></item><item><title><![CDATA[It's time for authorization standards: AuthZEN WG at OpenID Foundation]]></title><description><![CDATA[
<p>Article URL: <a href="https://www.aserto.com/blog/authorization-standards-authzen">https://www.aserto.com/blog/authorization-standards-authzen</a></p>
<p>Comments URL: <a href="https://news.ycombinator.com/item?id=38000167">https://news.ycombinator.com/item?id=38000167</a></p>
<p>Points: 11</p>
<p># Comments: 2</p>
]]></description><pubDate>Tue, 24 Oct 2023 15:01:38 +0000</pubDate><link>https://www.aserto.com/blog/authorization-standards-authzen</link><dc:creator>ogazitt</dc:creator><comments>https://news.ycombinator.com/item?id=38000167</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=38000167</guid></item><item><title><![CDATA[New comment by ogazitt in "OPA : Zanzibar :: SOAP : REST?"]]></title><description><![CDATA[
<p>Thanks! Analogies are always challenging, but the Zanzibar ReBAC model fits the “opinion” and “simplicity” of REST (at least when compared to SOAP).<p>We will definitely need the “Rails” equivalent for making ReBAC accessible to many more developers than it is today, and Topaz / Aserto definitely aims to be one of these! :)</p>
]]></description><pubDate>Wed, 19 Apr 2023 16:30:57 +0000</pubDate><link>https://news.ycombinator.com/item?id=35630185</link><dc:creator>ogazitt</dc:creator><comments>https://news.ycombinator.com/item?id=35630185</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=35630185</guid></item><item><title><![CDATA[New comment by ogazitt in "OPA : Zanzibar :: SOAP : REST?"]]></title><description><![CDATA[
<p>Good question. OPA is best suited for ABAC-centric scenarios, where your authorization logic is expressed in terms of attributes on users, objects, or environment.<p>The ReBAC / Zanzibar model is more opinionated, but most use-cases seem to be pretty easily described in ReBAC.</p>
]]></description><pubDate>Wed, 19 Apr 2023 15:38:08 +0000</pubDate><link>https://news.ycombinator.com/item?id=35629537</link><dc:creator>ogazitt</dc:creator><comments>https://news.ycombinator.com/item?id=35629537</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=35629537</guid></item><item><title><![CDATA[OPA : Zanzibar :: SOAP : REST?]]></title><description><![CDATA[
<p>Article URL: <a href="https://www.aserto.com/blog/opa-zanzibar-soap-rest">https://www.aserto.com/blog/opa-zanzibar-soap-rest</a></p>
<p>Comments URL: <a href="https://news.ycombinator.com/item?id=35628974">https://news.ycombinator.com/item?id=35628974</a></p>
<p>Points: 18</p>
<p># Comments: 4</p>
]]></description><pubDate>Wed, 19 Apr 2023 15:00:21 +0000</pubDate><link>https://www.aserto.com/blog/opa-zanzibar-soap-rest</link><dc:creator>ogazitt</dc:creator><comments>https://news.ycombinator.com/item?id=35628974</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=35628974</guid></item><item><title><![CDATA[New comment by ogazitt in "Show HN: Topaz: open-source authorization combining the best of OPA and Zanzibar"]]></title><description><![CDATA[
<p>Thanks! Let us know if you have any feedback!</p>
]]></description><pubDate>Wed, 26 Oct 2022 11:26:32 +0000</pubDate><link>https://news.ycombinator.com/item?id=33342163</link><dc:creator>ogazitt</dc:creator><comments>https://news.ycombinator.com/item?id=33342163</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=33342163</guid></item></channel></rss>