Skip to content
PlainID
← Back to all integrations
Access File Authorizer logo

Access File Authorizer

Extend PBAC to any system with this admin-time authorizer.

About PlainID + Access File Authorizer

The Access File Authorizer supports use cases requiring large-scale access calculations, maintaining authorization decision states, and generation of access files.

It generates access files based on predefined flexible structures, designed for use cases like reporting and auditing of policies, provisioning of access in non real time systems and legacy infrastructures. This solution effectively leverage centralized policy management and Authorization decisions in environments with limited real time integration capabilities or needs.

Technical Information

The Authorizer calculates bulk authorizations for a subject population and generates access files with the authorized objects. The technical flow of the Authorizer is based on 3 phases, starting by pulling a subject population, continuing with processing those through Policy Decision Point (PDP) requests, storing the Authorization decisions and finalizing it by converting the PDP decisions into a structured format of the generated access file.

This process can be triggered either by an API request or on a scheduled basis, offering scalability and flexibility integration and operation.

The resulting templated access file serves as an access report or as an input for access provisioning in non-integrated systems.

This supports:
1. Subject Data Loading: Loads subjects from predefined sources for authorization evaluation.
2. PDP Processing: Executes authorization calculations for each subject in parallel, storing results in an operational database.

3. File Generation: Outputs templated access files based on the stored authorization states, enabling offline access decision-making.

Architectures

Initiation

  1. An access file is generated, initiated either by an administrator or automatically through a scheduling mechanism.

Phase 1

  1. The Authorizer reads a list of subjects from the client’s data source.

Phase 2

  1. The Authorizer writes the retrieved subjects to an operational database.
  2. The Authorizer queries the PDP to calculate an Authorization Decision for each subject.
  3. The PDP's access decisions are stored in the operational database for each subject.

Phase 3

  1. The Authorizer generates an access file for all subjects and saves it in the storage volume.

Access Usage

  1. Applications retrieve and use the access file to enforce user access.
  2. User actions in the Application are approved or denied based on the Authorizations provided in the access file.

Technology

  • Other Platforms

Capabilities

  • Manage
  • Enforce

Auth Patterns

  • Application Authorization

Need help integrating?

Our experts can help you architect the perfect authorization strategy for your stack.

Contact Support

Better Together

Connect Context. Centralize Policy. Enforce Everywhere.