Asaf Cohen, Permit.io | KubeCon + CloudNativeCon NA 2022
Asaf Cohen, CTO & Co-Founder of Permit.io, joins Alan Shimel to give a deep dive into Permit.io, the only full stack permission solution on the market.
Transcript
This is texturing TV. All right. Hey everyone.
We're back. We're back in Detroit live on the show floor. I hope you've been watching our day two coverage.
Of course Mitchell Ashley our CTO and principal analyst has been doing some of our interviews today. Lessening the load on me. I appreciate it.
But I'm back here for this one and I'm happy to introduce you to a soft coin a sofas with a company called permit. io. And we are gonna find out about them right now Airsoft.
How are you? Hi, I'm great to be here great for to have you here. So it's off.
Well before we even get into permit. Let's hear a little bit about your story. How do you come here?
So my background is in cyber security. I used to be in the idea of intelligence forces money my time if anyone knows what it is 8200 and from there, I worked at a few cool companies in the industry. I was a software engineer at Microsoft.
I worked on the Xbox product. After that. I was one of the first engineers in a company called Clarity in cyber security and finally I was a software engineer at Facebook where I did developer tools for engineers within the company.
Very good. Yeah now I'm I'm the co-founder of permit good for you. Yeah, so I've got 25 years in cyber.
Pretty familiar with cyber. We didn't call it cyber. Yeah, we called it security.
Yeah. Um, but anyway, talk to me about Permit, what does it do? Yeah, so permit is actually the only full stock permission solution in the market.
So first of all, we need to understand what what why permissions are such a big problem so companies when they build software products, they have to do things like authentication understanding who they users are and there are plenty Solutions in the market like of zero in octoping identity, but after they understand who the user is so your Ellen, what are you allowed to do within my app what features can you access? What resources can you touch what database objects whatever and in order to build that it's a big it's a big challenge. So you have to model your system developers need to understand what role-based access control is how to do audit logs.
There's a lot of challenges here. So what for me is trying to do is basically give you an SDK an API that you can use to just do it within hours. Instead of months.
Okay just have it ready plug into your app and you have access control you have permissions. You have everything actually. Yeah.
So look, you know the big change. I I've seen big changes during my career, you know, and originally when I was in security it was it was very much the perimeter. mountain castle, you know around and You know, it was about Ingress and egress into the land.
Yeah with the Advent of cloud cloud native and you know. distributed networks distributed applications IAM identity and access management has become the Holy Grail right because that's how we control who has access to what in the clouds so forth and You know, it was a real problem. It is frankly.
It is a real problem, but it was a bigger problem. Early on in Cloud. We've come up with a lot of You know, there's now Cloud directories and the whole concept of zero trust.
Yeah, right. I'm not giving you access to anything because before was you had access to nothing or everything. Now it's you don't need access to everything and you don't need access to everything every time at all times.
So it's become much more sophisticated. Definitely, but from what you're saying. Permit allows you all of these things and more a very fine granularity.
Yeah, but almost like you said it once and then it's portable into different. Infrastructure, I'm on Google today on my AWS. I'm on Microsoft whatever.
Yeah, and I could move it so that the thing is permit can be used for infrastructure permissions. So Primitives like I am that you can actually embed within your application with your writing in the app. So yeah, you can just plug it in but typically you would use it for end user access and not for infrastructure access.
You can use it for infrastructure access. But our main goal is to make it easier for applications because for that you have nothing so you you do have today. I am solutions for infra and you can figure I am through stuff like terraform and palumi and whatever and whatnot and for applications you have nothing so permit is really and you yeah and you think in the market that you didn't have before yeah, so give me an idea of what is the What's the end user user experience like with permit?
Yes, so first there's the developer that starts implementing permit. So he gets apis and sdks and he can integrate into his application and we give him a low code policy editor that he can use to create a policy that says these are the users that allow this and these are the user about that. So for example, role-based Access Control, you can create roles and permissions and whatnot the end user and that's actually the special thing about permit can get and embeddable access components.
There are meant for him for end user. So if a company is a client of permit, they can embed and user experiences within their front end so they don't have to build that as well. So think about user management screen think about API Key Management think about impersonation features share sheets everything you need to delegate access to your end users and let them control them that themself And not bug you for that.
That's what we're trying to do. All right, I get it. That's a beautiful thing.
So how is this offer? You know, it's not a hosted service or anything? Yeah, how's it offered?
That's it sold. So that's a good question. So for me, it is a SAS solution that manages policy agents on your end.
So okay. Yeah the way it works. There's a lot of company in the in the markets that give you an API and say okay now ping my cloud every time you need to enforce access and say is this allowed or not, right?
This is not good for your app for a few reasons first latency. So even if they reduce the latency within their Network to one millisecond, it's still their Network latency. You are not in their Cloud so add to that and it cripples you're up and the second reason is resiliency.
What if they're cloudy is down. What if AWS itself is down. And they cannot control your app.
Your app is crippled. So what we do we give you an edge container that you put in your network that is controlled from the central cloud and can completely work offline and is independent of the central Cloud. So we just download updates every time there is a change.
Yeah, but we we are not the whole thing is completely different. Yeah working. Yeah the container so it's essentially a microservice within your app in your yeah that we give you the code and we manage it for you, but it's completely independent.
Yeah, beautiful and and How do you price it? Yeah, it's a good question. So first of all permit is a free up to 1000 users that you are enforcing access on every month.
Okay, but we actually look at usage based tears where the amount of users you enforce access to reflecting the price. So 2000 users. If you have them, that's great.
If you have 1 million users you get a different value from us, so it costs more and that's how it works. Excellent, man. I love it.
It's permit that I oh yes for me that I owe. Okay Cloud agnostic. I really does make a difference lives within the app itself.
Yeah. It's beautiful. Yeah.
Yeah, because that it's it's a different thing that authentication people are mixing them up, but fourth indication you can live in the Gateway if a company like off zero which I love by the way, it's a great company of zero is down you're good because most of your users have a Json web token and a session and they will continue accessing the app and they will recover in a few minutes and you'll be fine. But if if you don't do authorization authorization or permissions within your app locally if somebody else's Services down your entire application is crippled. So it's a different ball game.
Very big thing. It's it's a big thing. It's a huge difference.
Yeah, because the traditional Not just authentication. But yeah, the traditional model has been you go out. Whether it's a Sandbox or something, but you're dependent having it back.
Here is is a great thing. Yeah, um, it's interesting. How are you finding the show?
Oh, I love the show. We are seeing great engagement here at cubecon. So at the booth people are coming.
I see questions. We tell them about the product. We show them the new features we ask how are they solving permissions and access control?
What is looks like in the organization. They're great conversations Happening Here. I also saw great engagement insecurity con.
So I had a talk at securitycon about opal or open source offering sure and people were really interested. Oh, so I I do have this control playing for policy agents that is open source, and I can use and people really engage and we're really curious how this can solve their problems if they're building on their own. So there is a solution for that as well.
So I want to make clear is permit using oppa. So under under the hood permit uses policy agents and specifically Opa open policy agent as well and you can actually plug into that with your git and you can have pull requests that affect policy and you can review them and everything but we will support more policy agents in the future because we want to everything that the community uses we want to support because we don't want to force and use case on you want to be part of the solution. So it's important to support more policies.
Yeah, actually a soft. That's a great that was a great description. So it is permit that IO yeah check it out.
I think it's it sounds fantastic good new way to think about, you know application access here. We're gonna take a break. We'll be back in a moment.
