Authorization,
Supercharged
Drop Oso Cloud into your apps to quickly add RBAC, sharing, fine-grained access, or any other permissions model you can think of.









Your authorization code is holding you back
- Customers want features that you can’t build without a refactor.
- Your code is hand-rolled, fragile and hard to debug. It’s spread throughout the codebase and relies on data from multiple sources.
- There’s no one place to see who has access to what, that authorization is working, or why requests are or are not authorized.
Read about why authorization is hard
.png)

Oso Cloud is
Authorization as a Service
- Building blocks for RBAC, ABAC, and ReBAC.
- An opinionated but flexible data model.
- One place for all your authorization decisions.
- Debugging tools to show you why access was granted.
- Logging for a full record of authorization decisions.
- High performance: nodes deployed in regions close to your application for <10 ms response times.
- Reliability & resiliency: multiple replicas in regions worldwide to protect your app against downtime.
How Oso Cloud works
1
Model
- Lay out who’s allowed to do what.
- Start with primitives for common patterns like multi-tenancy and RBAC.
- Express custom rules using Polar, our declarative policy language for authorization.

2
Store
- Put your core authorization data, like roles and permissions, in Oso Cloud.
- Send any other data at request time as context.

3
Enforce
- Make simple checks with a call to authorize().
- Use other APIs for filtering resources, listing a user's roles, or rendering your UI.
- Write custom queries for anything else.

4
Debug, Test, & Monitor
- Debug your setup using Explain.
- Write tests over your policies before you push them live.
- See logs of authorization decisions in real time.

Looking for Oso On-Premises?
If you have strict on-premise requirements, build using the open source Oso Library on your own.