3 ms·
It's a fair question, but in fairness to Carta, until recently, there have been ~zero commercial or open source solutions to building application authorization
by gneray 5y ago
It's a fair question, but in fairness to Carta, until recently, there have been ~zero commercial or open source solutions to building application authorization (beyond limited helper libraries or things like Active Directory, which solve only a portion of the problem). Developers have typically figured out the models on their own and implemented them in application code with IF statements, etc. and/or by building separate authorization services. Other publicly documented examples include teams at Slack (https://slack.engineering/role-management-at-slack/ https://slack.engineering/role-management-at-slack/) and Gusto (https://engineering.gusto.com/layering-authorization-into-a-web-application/ https://engineering.gusto.com/layering-authorization-into-a-...)
OPA is one solution that's emerged in recent years. The author describes his team's point of view after evaluating it for their purposes.
Oso (https://www.osohq.com/ https://www.osohq.com/) is a framework for application authorization. Disclosure: I'm a cofounder. Based on the post, the Carta team started their work in 2019, but we only open sourced Oso mid-2020, so they wouldn't have known about it.
And in the last few months, a few other companies have announced offerings to address this problem too.
So it's understandable why Carta chose to build. Now/soon other teams like them should have more options to choose from when they encounter similar challenges too.