In conjunction with

Zanzibar-Inspired Fine-Grained Authorization Infrastructure Built on Open-Source SpiceDB

Authorization is the whole of AuthZed's product surface: the company builds infrastructure that answers "can this subject do this thing to this resource" for application and platform engineering teams. Its founders came out of Red Hat and CoreOS, where Jake Moshenko and Joey Schorr — who met on Google's APIs team — created the Quay container registry, with Jimmy Zelinskie joining as Quay's first hire. The company is backed by Y Combinator, General Catalyst, Amplify Partners and Work-Bench.

The engine underneath is SpiceDB, an open-source permissions database modeled on Google's Zanzibar paper. Rather than evaluating policy files, it stores relationships between objects and resolves permissions across that graph, using a schema language that defines object types, relations, computed permissions and caveats for attribute-style conditions. A distributed parallel graph engine answers checks over gRPC and HTTP/JSON APIs, with a per-request consistency model designed to resist the New Enemy Problem. Backing stores include PostgreSQL, MySQL, CockroachDB, Spanner and in-memory.

Commercially the technology ships as AuthZed Cloud, AuthZed Dedicated for isolated instances, and SpiceDB Enterprise for self-deployment, alongside a Kubernetes operator, client libraries and an MCP server. Recent work targets AI systems: permission-aware retrieval so RAG pipelines return only documents a user may see, tenant isolation, and pre-execution guardrails giving agents scoped, time-bound, audited access. Named users include OpenAI, Workday, Turo, Redpanda and Netflix, which sponsored SpiceDB's ABAC-style capabilities.

Market Segments:

Identity SecurityAI Security

Categories:

Identity and Access Management (IAM)Agent SecurityAI Security