Home / Companies / Oso / Blog / August 2025

August 2025 Summaries

3 posts from Oso

Filter
Month: Year:
Post Summaries Back to Blog
Apple has hired the core maintainers of the Open Policy Agent (OPA) and several Styra engineering team members, leading to the open-source community taking over the maintenance of Styra's commercial products under the CNCF. This shift raises questions about OPA's commercial offerings like Styra DAS, which may face challenges in terms of innovation and enterprise support, though OPA itself remains a stable CNCF project. This scenario is reminiscent of Apple's 2015 acqui-hire of the FoundationDB team, whose technology is now primarily developed for Apple's internal needs. As a result, organizations relying on Styra's commercial tools might consider alternatives such as Oso, which focuses on application-level authorization with a tailored approach to permissions models like RBAC, ABAC, and ReBAC. Oso positions itself as a viable, developer-focused, and commercially supported alternative, particularly for teams needing to implement specific permissions models rather than general-purpose policy engines.
Aug 20, 2025 590 words in the original blog post.
A virtual roundtable discussion hosted by Oso, featuring Will Bengtson from HashiCorp and moderated by Gabe Jackson, explored the impact of AI on security threat models, developer workflows, and the role of security teams. Key insights included the importance of understanding AI tools to set effective policies, shifting from a blocking to an enabling approach, aligning AI tools with business goals, and adapting security processes to the speed of AI advancements. Will Bengtson emphasized the need for early governance and strategic use of AI to enhance security operations, like automating triage and vulnerability analysis. He also shared his perspective on authorizing and managing AI tools, drawing on his experiences at Netflix and HashiCorp, and highlighted his advisory role at Oso due to its centralized authorization capabilities. The roundtable concluded with recommendations for security leaders, particularly in fintech SaaS environments, to align security measures with business objectives while embracing AI's potential to transform security practices.
Aug 19, 2025 592 words in the original blog post.
The official Oso MCP server has been launched to facilitate the integration of AI tools with the Oso Cloud API, aiding in learning Polar, debugging applications, and developing new features. The Model Context Protocol (MCP) standardizes interactions between LLMs and external tools, fostering a plugin-style ecosystem that allows users to utilize various tools and resources with any compatible client. This server helps AI tools connect with the Oso platform to explain policies, answer questions, or write tests. To set up, users create an API key and configure their AI clients. MCP supports evolving developments like Streamable HTTP transport for stateless servers, and the Oso team is open to feedback on policy testing, fact querying, and authorization debugging to enhance the server's capabilities.
Aug 07, 2025 447 words in the original blog post.