Skip to content

AuthZed

AuthZed builds and commercially supports SpiceDB, a Google Zanzibar-inspired open-source permissions database used to enforce fine-grained authorization at scale.

Visit Website ↗ + Add to Compare
72/100Meaningful Innovator

Overview

AuthZed develops SpiceDB, an open-source authorization database modeled on the design Google published for its internal Zanzibar permissions system. Rather than embedding role checks directly into application code, SpiceDB lets engineering teams model complex, relationship-based access rules (who can see this document, who inherited access through a team or folder, who was explicitly denied) as a graph that can be queried consistently at low latency and enormous scale. AuthZed sells hosted and dedicated deployments of SpiceDB along with support, positioning the product as infrastructure for authorization the same way a cloud database vendor sells infrastructure for storage.

The company’s most visible reference deployment is OpenAI, which uses AuthZed’s infrastructure to enforce document-level permissions across ChatGPT Enterprise’s connector ecosystem, reportedly evaluating tens of billions of fine-grained permission checks so that search and retrieval results respect each user’s actual access rights rather than a coarse, app-level entitlement. AuthZed also lists Workday and Turo as production customers using SpiceDB or AuthZed Dedicated to unify access control across sprawling internal systems.

Fine-grained, relationship-based authorization has become a distinct pain point as organizations connect LLMs and AI agents to internal data stores: a chatbot that can technically read every document in a corporate drive is a data-leakage incident waiting to happen unless permissions are enforced consistently at query time. AuthZed’s pitch to CISOs is that retrofitting Zanzibar-style authorization into RAG pipelines and agent tooling closes that gap without forcing every team to hand-roll its own permission layer.

Innovation Matrix Assessment

Innovation Velocity 7/10

Founded in 2020, AuthZed has shipped a mature open-source database (SpiceDB, 6K+ GitHub stars) plus hosted/dedicated commercial offerings, and has expanded its product line specifically toward AI agent and RAG authorization as that need emerged in 2025-2026, showing a steady release cadence rather than a one-time launch.

Operational Value 6/10

AuthZed is a roughly 35-40 person company running production infrastructure for large enterprise workloads (OpenAI's ChatGPT Enterprise connectors). That is a lean team to operate at the scale claimed, which is a genuine efficiency signal but also a concentration risk worth noting for buyers evaluating vendor resilience.

Market Momentum 7/10

The company is a Series A business backed by General Catalyst, Work-Bench, Amplify, and Y Combinator, and is reported to be preparing a subsequent round; named customer additions (Workday, Turo, OpenAI) over the past two years indicate real commercial traction rather than only open-source download growth.

Category Disruption 8/10

SpiceDB's Zanzibar-style relationship graph model is a materially different approach to authorization than the RBAC/ABAC libraries most engineering teams build in-house, and AuthZed was early to reposition this specifically for LLM/RAG and AI-agent data-access enforcement, a problem most legacy IAM vendors were not built to address.

Real-World Efficacy 7/10

The OpenAI ChatGPT Enterprise deployment, independently reported by multiple outlets and detailed in AuthZed's own customer case study, describes tens of billions of permission checks in production; Workday and Turo are also named production customers. These are credible, named references rather than anonymous logos, though the specific performance/latency numbers come from AuthZed's own case study and have not been independently benchmarked.

Enduring Relevance 8/10

Fine-grained authorization is becoming a first-order security control as enterprises connect LLMs and AI agents to sensitive internal data stores; a CISO evaluating any RAG or agent deployment needs an answer to 'does this respect existing permissions,' which is exactly the gap AuthZed targets.

Why CISOs Should Care

As organizations wire LLMs and AI agents into internal document stores, a permissions gap becomes a data-leakage incident; AuthZed gives security and platform teams a way to enforce the same fine-grained access rules at AI-query time that already exist in source systems, instead of relying on coarse app-level entitlements.

What Makes It Different

Most authorization tooling is either a hand-rolled RBAC layer or a policy-engine product (e.g., OPA-style); AuthZed's SpiceDB implements the Zanzibar relationship-graph model Google uses internally, which handles deeply nested, inherited, and denied permissions at a scale and consistency level that simpler role-based systems were not designed for.

The Matrix Verdict

72/100 — MEANINGFUL INNOVATOR

AuthZed is a focused, technically credible bet on a real and growing problem -- fine-grained authorization for AI-connected systems -- with a named reference customer (OpenAI) operating at genuine scale. It is an infrastructure dependency rather than a full IAM suite, so it fits best as a component alongside existing identity providers rather than a replacement for them.

Editorial Note: Claims vs. Verified Findings

Independently verified: Series A funding and investor list (General Catalyst, Work-Bench, Amplify, YC) are corroborated across Crunchbase and press coverage; the OpenAI, Workday, and Turo customer relationships are named and cross-referenced in multiple outlets. Vendor-sourced and unverified: the specific 'tens of billions of permission checks' throughput figure and any latency benchmarks originate from AuthZed's own OpenAI case study and have not been independently measured or audited.

Sources