Home / Companies / AuthZed / Blog / Post Details
Content Deep Dive

Policy-Based Access Control (PBAC) vs Google Zanzibar: When You Should Use One or the Other

Blog post from AuthZed

Post Details
Company
Date Published
Author
Evan Cordell
Word Count
1,843
Company Posts That Month
4
Language
English
Hacker News Points
3
Post removed?
No
Summary

At AuthZed, they are building a platform around SpiceDB - an open-source, ReBAC-based authorization system inspired by Google Zanzibar. They have explored the differences between policy-based access control (PBAC) and ReBAC, highlighting that while PBAC solutions often use standard software development lifecycle tools and techniques, ReBAC systems like SpiceDB store relationships as facts and define a schema to relate these facts into a graph. This approach allows for more flexibility in handling authorization questions, including RBAC and ABAC. The authors argue that when all data for a policy decision can be statelessly derived from a policy engine, they tend to shine, but when external data needs to be queried, the performance of policy engines may not guarantee fast evaluation times. The authors also discuss their own use case at AuthZed, where they mix different approaches, including using a dedicated SpiceDB instance for permissions in the Serverless platform and leveraging policy-like features from Kubernetes projects. They highlight that whether PBAC or ReBAC is better suited depends on the authorization problems encountered.

Trends Found in this Post
Trend Post Mentions Total Month Mentions Posts Companies MoM
Kubernetes 7 1,704 191 78 +3%
Serverless 2 1,008 161 77 +55%
Use This Data

Use this post, company, and trend context to find content marketing opportunities, perform competitive analysis, or address product feature gaps via the Plushcap MCP server or the Plushcap API.