
Or Weis
Announcing Permit MCP Gateway
Announcing Permit MCP Gateway, a new trust and enforcement layer for MCP that brings identity, consent, fine-grained authorization, auditability, and runtime control to AI agent actions.


Featured Stories

Or Weis
Announcing Permit MCP Gateway, a new trust and enforcement layer for MCP that brings identity, consent, fine-grained authorization, auditability, and runtime control to AI agent actions.

Gabriel L. Manor
The new Permit.io CLI brings developer-first workflows to access control. Define, test, deploy, and enforce fine-grained authorization using AI, CI/CD, GitOps, and OpenAPI — all from your terminal

Or Weis
An AI agent audit trail binds identity, delegation, tool, resource, policy, allow/deny, HITL, and outcome. Tool traces are not enough.

Or Weis
SOC 2 CC6 and ISO 27001 access control checklist for AI agents: what controls assumed, how agents break them, evidence to produce.

Or Weis
Regulators’ “prove it” maps to PEP + PDP + decision logs: enforce in the app, decide in a local PDP synced by OPAL, and keep explainable allow/deny evidence.

Or Weis
DORA and NIST do not prescribe a vendor. They expect scoped least-privilege access and attributable logs, including for NHIs and agents. Application FGA with decision logs is how product teams produce that evidence.

Or Weis
AI agent permissions usually inherit the user OAuth token. That fails least privilege. Give the agent its own role at each tool call.

Daniel Bass
RBAC grants access by role; ABAC evaluates user, resource, and environment attributes. Compare them side by side, see examples, and learn how to migrate from RBAC to ABAC.

Or Weis
Your authorization model shapes least-privilege evidence in access reviews. Role assignments, attribute conditions, and relationship tuples each prove different things.

Or Weis
Hybrid authorization by default: RBAC for org roles, ABAC for context, ReBAC for sharing graphs—one check API across models. How to pick a stack before role explosion, and why least privilege needs explainable entitlements.

Or Weis
Authentication (AuthN) is who you are; authorization (AuthZ) is what you're allowed to do. Learn 401 vs 403, why IdPs don't replace app AuthZ, and how to externalize permissions.

Or Weis
SOC 2-style access reviews need more than IdP login events. Explainable allow and deny decision logs — decision provenance from identity to policy to resource — are the authorization evidence that makes application-level access controls concrete.

Or Weis
Every authorization decision should be explainable. Authorization observability is not more logs — it is decision provenance. Here is how to build an audit trail that answers why access was allowed or denied.

Or Weis
Fine-grained authorization belongs in a dedicated control plane—not scattered if-statements. Learn when to externalize authorization and stop rebuilding DIY RBAC in application code.