Startup DreamersStartup Dreamers
  • Home
  • Startup
  • Money & Finance
  • Starting a Business
    • Branding
    • Business Ideas
    • Business Models
    • Business Plans
    • Fundraising
  • Growing a Business
  • More
    • Innovation
    • Leadership
Trending

Nvidia Packs Data Center AI Into A Desktop Box

October 17, 2025

‘Sovereign AI’ Has Become a New Front in the US-China Tech War

October 17, 2025

‘NYT Mini’ Hints And Answers For Thursday, October 16

October 16, 2025
Facebook Twitter Instagram
  • Newsletter
  • Submit Articles
  • Privacy
  • Advertise
  • Contact
Facebook Twitter Instagram
Startup DreamersStartup Dreamers
  • Home
  • Startup
  • Money & Finance
  • Starting a Business
    • Branding
    • Business Ideas
    • Business Models
    • Business Plans
    • Fundraising
  • Growing a Business
  • More
    • Innovation
    • Leadership
Subscribe for Alerts
Startup DreamersStartup Dreamers
Home » Managing Fine-Grained Access In Multicloud Environments
Innovation

Managing Fine-Grained Access In Multicloud Environments

adminBy adminSeptember 6, 20231 ViewsNo Comments5 Mins Read
Facebook Twitter Pinterest LinkedIn Tumblr Email

Head of Standards for Strata Identity, former Burton Group analyst and technology executive at Chase Manhattan Bank (now JPMorgan Chase).

Cloud computing has been a great enabler to enterprises, speeding up operations and allowing organizations to move up the digital maturity journey faster and more effectively. However, multiple clouds—especially when they have to intersect with on-premise systems and one another—can produce some challenges I’ve discussed before.

Many organizations can end up with an “identity gridlock” of competing identity systems and protocols since each cloud platform cannot exchange access policy data with other cloud providers. Identity orchestration offers some relief to this balkanization of access management, but in the end, an enterprise wants a unified, policy-based framework to manage access to its assets and enforce access controls.

Zero trust, least privilege and just-in-time access are all solid strategies and approaches to creating a secure environment that can be greatly enabled by a philosophy of fine-grained access control.

This idea of fine-grained access is similar to accessing an office building: Swiping an ID card at the entrance to the elevators confirms a user is authorized to enter the premises. It can give a user access to enter the building—all floors, all conference rooms and all offices, from the break room to the money vaults and server rooms. On the other hand, the card may only give employees access to those floors where they work, to their own offices or to the lab or workshop where they are authorized to be. A chemist can walk into the lab, while an entry-level office worker may only have access to the cafeteria and the cubicle pool on their floor.

In the digital world, fine-grained access limits an identity to those applications and assets the user requires for their job function. However, unlike coarse-grained control, which uses only one marker to grant or revoke access—such as the user’s job function—fine-grained authorization is ruled by multiple factors in tandem, such as the right user accessing the network from the right IP address in the right geographic location.

Fine-grained access can also adapt to conditions based on certain attributes—for example, a user logging on from outside of their usual network or IP address may be authorized to open a file on read-only mode with no permission to make edits.

Fine-Grained Access Needs Standards

This sounds like an ideal state of affairs, but it faces some hurdles—starting with the lack of interoperability. There are industry standards such as the Extensible Access Control Markup Language (XACML) (de facto) or Open Policy Agent (OPA) (de jure) as well as open-source options like the Amazon Cedar policy language that was announced in May 2023. Many proprietary models also exist, whether within cloud platforms themselves or in stand-alone authorization products.

However, large enterprises are frequently deploying applications across multiple clouds, and they’re using several incompatible identity systems. The marketplace is missing an approach that allows for policy interoperability. Standards such as SAML and OIDC have helped with federating identity and enabling single sign-on across security domains, but policy interoperability will require a new approach to address this long-standing need.

A newer initiative with the CNCF, called IDQL/Hexa, aims to function as a master key that can get users where they need to be by creating an approach whereby a common access policy can be translated into the runtime format used by standards-based, open-source or even proprietary access systems. This approach aims to eliminate the manual work and duplicated effort required to manage policies in each distinct identity system.

The Road Ahead For Standards Like IDQL/Hexa

Building and introducing a new standard in the identity or security industry follows a typical pattern where 1) the problem area is recognized, 2) a group forms to begin scoping and specifying a new approach, 3) additional groups (vendors and enterprises) join the effort, 4) the effort is taken up by a standards organization, and 5) a new standard ultimately is ratified.

There can be challenges along the way, of course, where incumbent players are satisfied with the status quo, and it can sometimes be difficult to make compromises with your real or perceived competitors. However, the industry has a pretty good track record of standards that have been published by the likes of ITEF, OASIS, OpenID Foundation and others.

Overcoming issues, challenges and disagreements during the standards-making process requires a lot of open dialog and debate. Ultimately, vendors and enterprise customers work toward building a consensus and doing what’s best for the industry.

A declarative and interoperable format that serves as a common language for implementing and orchestrating policies needs to emerge. Thanks to a number of open-source and standards-based initiatives, there are candidates to be the standard-bearer in this endeavor, which makes it an exciting time to be part of this industry-shaping effort.

Forbes Technology Council is an invitation-only community for world-class CIOs, CTOs and technology executives. Do I qualify?

Read the full article here

Share. Facebook Twitter Pinterest LinkedIn Tumblr Email

Related Articles

Nvidia Packs Data Center AI Into A Desktop Box

Innovation October 17, 2025

‘NYT Mini’ Hints And Answers For Thursday, October 16

Innovation October 16, 2025

‘NYT Mini’ Hints And Answers For Wednesday, October 15

Innovation October 15, 2025

Microsoft’s Free Windows Offer—You Have 24 Hours To Act

Innovation October 14, 2025

TP-Link Announces Breakthrough By Demonstrating Its First Wi-Fi 8 Connection

Innovation October 13, 2025

Jaron “Boots” Ennis TKO’s Lima – Critics Still Unsatisfied

Innovation October 12, 2025
Add A Comment

Leave A Reply Cancel Reply

Editors Picks

Nvidia Packs Data Center AI Into A Desktop Box

October 17, 2025

‘Sovereign AI’ Has Become a New Front in the US-China Tech War

October 17, 2025

‘NYT Mini’ Hints And Answers For Thursday, October 16

October 16, 2025

‘NYT Mini’ Hints And Answers For Wednesday, October 15

October 15, 2025

Inside Intel’s Hail Mary to Reclaim Chip Dominance

October 15, 2025

Latest Posts

How China Is Hoping to Attract Tech Talent

October 14, 2025

TP-Link Announces Breakthrough By Demonstrating Its First Wi-Fi 8 Connection

October 13, 2025

This Startup Wants to Spark a US DeepSeek Moment

October 13, 2025

Jaron “Boots” Ennis TKO’s Lima – Critics Still Unsatisfied

October 12, 2025

Google Quietly Upgrades Chrome For All 3 Billion Android Users

October 11, 2025
Advertisement
Demo

Startup Dreamers is your one-stop website for the latest news and updates about how to start a business, follow us now to get the news that matters to you.

Facebook Twitter Instagram Pinterest YouTube
Sections
  • Growing a Business
  • Innovation
  • Leadership
  • Money & Finance
  • Starting a Business
Trending Topics
  • Branding
  • Business Ideas
  • Business Models
  • Business Plans
  • Fundraising

Subscribe to Updates

Get the latest business and startup news and updates directly to your inbox.

© 2025 Startup Dreamers. All Rights Reserved.
  • Privacy Policy
  • Terms of use
  • Press Release
  • Advertise
  • Contact

Type above and press Enter to search. Press Esc to cancel.

GET $5000 NO CREDIT