$6 Million Seed Funding – Or Weis, Permit.io
Permit.io recently launched out of stealth with $6 million in seed funding to help developers easily build permissions into their cloud native applications.
Transcript
This is texturing TV. Hey everyone. We're back here on Tech's drug TV.
io website, and I've had the pleasure of interviewing or in person. As well as here on Tech strong or first of all, welcome back. I hope all is well with you.
Thanks for having me. It's a great being here since we last talked. I've become a parent myself of for you marble countries.
They say over here in Florida. Thank you very much. And and I'm excited in Florida.
Yeah for sure also here in Israel. And we're kind of excited on both raising a human being and raising a startup then I keep saying common themes between the two. and there are some common things but Well, you'll feel there's nothing better than raising a human being.
I love my startups, but You'll see you'll see you'll say I told you anyway, so or congratulations on that for those who may be their people out here maybe who have heard of permit or are not have not heard of permit. Why don't we just quickly give a quick level set what permit IO does Sure. So permanent is a solution to add permissions to your product with the premise of you never having to build permissions again, if you ever use software in the past and I bet you did you probably notice that there are a lot of Access Control experiences built into that to name a few user management with their ability to assign roles API Key Management audit logs multitensy approval flows.
It's different and every time you saw those some Porsche lap of a developer had to create them from scratch. So instead of doing that over and over and wasting time you can use permit and actually focus on building your product and be confident that you're having the best access control that is available out there. Actually, all right.
So I think we've laid the groundwork. I wanted to spend the bulk of our time today talking about a new offering from permit. I think you call it permit elements.
Right. So permanent elements kind of like stripe elements. We've we've we took a lot of inspiration from how they build their software.
So I've kind of touched on this and with the premise when you're building software, there's a lot that you need to do with Access Control. Some of it is in the back end in the enforcement itself and how you create infrastructure to enforce access in real time and use things like policies code and the event within architecture that supports that but another thing that you need is also the experiences for the end customers and for the upper stakeholders you want for example, when your product managers need to add another role into this system you want them to be able to do it on their own when your customers want to see what they did within the system you want to enable them to do that on their own so they don't have to bug you for every little thing and in the end of the day, it's okay you have options you ever build these experiences yourself or you use permit and you have them ready made and you bake them into your software. So we provide them as iframe and then as react components and their customizable enough so you can enjoy the power of them, but still have them on brand and on theme of what you're building.
Um, and it's just like with with stripe, for example, if you want to add a shopping cart, or if you want to add the billing page you you'll be able to take those ready-made elements and embed them to your software and with permit. It's the same if you want the audit log screen, if you want user management with those roles, if you want another user to be able to ask permissions from a from their colleagues that's already for you to use. You don't need to build it and there's a lot of smart mechanics to build into that and we can also talk about how by using these mechanics everyone kind of benefits because of the smart on their layers.
The user Behavior analytics are kind of shared between accounts. I love it. So of course look this this is oh user access and and control is you know in my mind, it's the killer app in the cloud, right?
It's the killer kind of security piece in the cloud as well. I always like you mentioned stripe has something called elements, but of course, this is different, right? What what?
What drove you and the team to say? Hey, you know what? This is.
This is something that's needed. This is how we should do this. Um bottom line our customers.
So when we was always for customer Yeah, the customer is always right and you better listen and I think something that is unique to us and even brag and saying we we are developers ourselves. We've been Hands-On developers till the moment we found that the company and also a lot within the company itself and we realize something that I think some of our competitors haven't I think when you talk to our competitors and you ask them what what do developers want they'll say things like developers want really complex technology that enables them to build amazing things and while that's true on the surface it kind of misses the point in the authorization space because in the authorization space and in similar Fields developers basically don't give a rats ass about this they want to focus on actually building their product absolutely once and then and then no yes that it's a lot of friction from the core things that you want to do. Just like you don't want to build your own encryption.
Just you don't want to build your own authentication. You don't really want to build your own authorization. So by just providing them with a policy engine or just providing them with the infrastructure or apis to build this you're not really solving the problem for them.
You're living most of the pain on the table for them to tackle. And that's that's not the right way of think to approaches. I think the right way is to take this and to end off the table.
So developers can focus on what they actually care about but building their core features and product and in order to do so, you need to take care of the experience and to end you need to deliver the interfaces the UI components themselves that the developers can delegate their fellow stakeholders products security confines support Professional Services and most importantly to the end customers themselves when the end of the day need to be able to work with that software with those access. all elements or expenses got it. Or this is available right now.
Yeah, it's available for everyone in self-service. You can just go into permit and we kind of guide you to both apply the enforcement itself apply the SDK or plugins that will actually toggle access. Within your application, but we also enable you to start right off with the elements themselves.
If you want to use your management screen, if you want API Key Management, if you want audit logs, you can use those independently of the enforcement itself. Obviously if you use it with the enforcement it kind of you gain the benefits of the two. So for example, when you enforce access that automatically generates audit logs, you don't need to like call a number API to register the fact one user try to perform an action that automatically gets registered just by you checking for Access.
So it will automatically populate for your customer the ability to see what they did within their tenant. loving So you can get itself. So what would cost how do you you know, you're looking better make money?
Yeah, so we're a plg companies or we're using usage based pricing. So the main metric is how many monthly active users you have? Meaning?
How many identities you check permissions for in a monthly basis. So it doesn't matter how many authorization queries you do or how many instances of permit you Deploy on your side. We provide a microservice for for authorization for you.
So you can deploy that as many instances of that as you want and it scales with your software in the end of the day you only care about how many identities you check permissions for. io encourage everyone to go check it out. for I want to Yep, a little bit.
So an Ann. ouncement came out from Amazon about a I guess it's a new language really like around around, you know accessing control. Tell us about maybe I'm assuming you know about it.
Tell us about it a little bit. I don't. Actually printed about it.
So f****** inspiration from Amazon and a lot of people have been looking at the Amazon in the AWS. I am how you do like access control for infrastructure components within within AWS and that is kind of been misleading people. They've been coupling the infrastructure level access control that they have with their own application Level.
So for example, the couple the application Level access control with access to an S3 bucket, for example, that's a very bad idea in Amazon is recognized that as well. And and they've said okay, we need an application Level Access Control solution that people can use and in the intern between before Amazon coming in over her players, like open and also is maybe another example have created policy engines for people to use and some of them have become popular. But what's unique here is that Significant player like AWS is coming in says yes, a policy language is something that we need application Level authorization and something that we need to address and we can't copy it with our infrastructure level access control and there's a room for a language here that will be simple enough for people to use in the cloud.
So this is first I think it's a it's it's an important step in the maturity of this space in the maturity of authorization languages and it's also an important step in how we see the market a lot of the other players. I'm like permit are have been kind of tooting we have our own policy engine. You should use only that we from day one said which this should be engine agnostic.
We should support multiple languages because you need the right tool for the right task. And now AWS is adding a very significant tool to this toolbox. So we've kind of adopted it very early on so this I think in general increases the maturity of this entire space think this brings this into awareness for everyone.
But it also raises a lot of interesting questions. So AWS took a step forward with this. What about other clouds Which languages would you use when you're working cross between multiple clouds or you you working with hybrid Cloud?
How would you work with this with maybe some still on-prem deployments that you have? So we're trying as permit. We're trying to answer that as well.
We're providing a layer on top that you can use both of and Cedar and with our languages but as a whole there the market still needs to kind of decide on this and I think we're just seeing the start of the both the complexity and the new solutions that are going to be coming in from the big vendors and the small vendors alike. actually, you know from times when you're in aws's position, right you can you can really kind of force the market. In One Direction or another and imposed imposes a bad word.
But you know strongly suggest. Right a particular way of doing it. Of course.
The question comes up though. Well, what about what about people who are on Azure or you know GPC? Right.
Does this solution have legs enough to carry over to make it truly industry white? What is it becoming AWS and remain in AWS only language. So it remains to be seen I think a lot of this depends on how they they decide to release it to the market so far, if only opened this for a close beta and they've already released specs on the language and not the language itself or any engine where you can play with language.
So it's not open source, for example, if they'll open source that might create a different situation but I actually wouldn't count on that at the moment. So we're likely to see our implementations of this. We're likely to see our engines kind of complement this and I think most importantly we'll be seeing bridge in components that allow you to leverage the different policy languages within the different clouds or different deployments as you need them, but it's still early days.
So it's I think most of the interesting things are our head of us and I'm personally I'm super excited about this. We're literally building the standards here that will guard applications for for generations to come. I I don't disagree with you at all.
Hey, man, it's great catching up with you. We were talking a little off camera. You'll be a cubecon up in Amsterdam.
Yes mean person in the entire team and I look forward to connect a few there as well. And with our the rest of the audience listening to us. I'll be more than happy to catch up with all of the attendees.
For sure, we will man. It's great seeing you are congratulations on being a parent. That's really the best job you're ever gonna have enjoy every second it goes quickly to they grow up.
But keep doing what you're doing your permit as well and we'll be in touch. Thank you very much. io here.
I text drunk. We're gonna take a break. We'll be right back.