foreword
I’ve spent an inordinate amount of time trying to convince people that authorization is interesting. Personally, I find it fascinating. What is allowed? What is banned? Why? What if I ask for access in a different way? And it’s even more fascinating in the age of AI because an agent can ask for access in a million different ways within a minute. How do we give these eager, helpful agents safe sandboxes in which to do their work? Phil Windley has written the book I have been waiting for someone to write that takes these questions seriously.
For you, dear reader, who may be new to authorization, reading this book will feel like watching a master craftsman lay out his tools and explain, patiently and without showing off, why each one exists. I am one of many folks who helped build the Cedar policy language. I was the product manager, which meant that it was my job to balance and decide on which tools to include and how they would work. Authorization in Action is the only place where you can read the rationale behind those decisions and fully understand how to use authorization tools in the way they were intended.