Someone pointed a load test at Zanzibar's production environment by mistake. 10 million extra QPS.
"We didn't notice." Nobody got paged. Nothing fell over.
Episode 6 of base-layer, with Ari Shamash, formerly of Google's Zanzibar team, is out now.
AI that asks permission, not forgiveness.
At ClawCon Seattle, @samkim demoed SpiceClaw: fine-grained permissions for OpenClaw agents, so they only touch the data you intend.
Plus talks from @OpenClaw and @awscloud. Full recap: https://t.co/flbhSaCwdI
Rule from episode 5 of base-layer, worth remembering before episode 6 drops Thursday:
Don't let the agent decide if it needs authorization.
The moment the agent makes that call, your access control stops being deterministic.
Zoom's agentic search spans *many* third-party data sources, each with its own permissions. Their homegrown authz couldn't scale.
They chose AuthZed Dedicated. Now: sub-50ms checks at intense scale.
Full story: https://t.co/DXtYLW1OXH
Everyone's had the same idea this year: use more AI to secure AI.
Sohan Maheshwar says that's backwards. AI is probabilistic. Access control needs to be deterministic. Throwing more of one at the other doesn't make it more secure.
Episode 5 of base-layer is out now: https://t.co/JUuDgvSndr
When @Calendly's Notetaker AI needed to share recaps across users, groups, and workspaces, their ad hoc authorization couldn't keep up,
They adopted SpiceDB to standardize access control. Now GA, checks running 25-30ms.
https://t.co/yIoSxEVBNs
Taylor Dolezal's commit history used to sit near zero. Now a device in his family room shows the trailing 30 days: 2,700 commits.
Episode 4 of Base Layer, with @onlydole of @dosu_ai, is out now.
https://t.co/uex2oT0I0q
AuthZed Materialize is now Generally Available for AuthZed Dedicated 🎉
Precomputes your most expensive permission checks in advance. Single-digit millisecond responses, even at enterprise scale.
https://t.co/ccFlobsGBR
Spencer Kimball co-created GIMP in 1997, then went on to found @cockroachdb.
His take: governance, not capability, is what's actually blocking AI adoption.
Episode 3 of base-layer is out now.
https://t.co/uaELj1botm
She built a hair-care app for herself, used it for months, then deleted it.
Emilie Schario of @kilocode calls it selfieware: no users, no tracking, no authorization. Built because the cost of building dropped below the cost of caring.
Listen here: https://t.co/lmrnqpEBbx
Seats are still open for Thursday's roundtable on permissions in agentic AI, hosted by AuthZed CEO @JacobMoshenko
Past attendees have come from Pinterest, Turo, NBA, and Adobe.
If you're building internal AI systems, this is for you. https://t.co/5HgwpsdB1u
"I think you just can't trust pretty much any of your
infrastructure."
EP 01 of base-layer is live with @zsmithnyc of Datum on why the
internet needs an upgrade.
https://t.co/LLmmsn40yt
We once made a video modeling Discord's permissions in SpiceDB. It took over an hour.
This time, one prompt got us there. The SpiceDB Playground Assistant writes the schema, generates test data, and validates it, live in your browser. Ask it why a check fails and it shows the actual trace, not a guess.
"Why can't alice view budget.pdf?"
Ask the SpiceDB Playground Assistant and it won't guess. It pulls the real debug trace and names the exact relation that's missing.
Try it: https://t.co/GrsmuM000t
Your AI agent inherits real access to real systems the moment it touches your deploy pipeline.
We built a DevOps agent with @goose_oss and SpiceDB. Revoke its staging access, and prod access disappears automatically. No RBAC flag can do that. A relationship in the schema can.
#AIAgents #DevOps #ReBAC