LATEST / 10 SEP 2026
AuthZed Materialize reaches general availability for Dedicated CloudPrecomputed permissions for applications and AI
Company / Authorization infrastructure

AuthZed and the art of saying no

A car-sharing rollout escaped its borders. An AI assistant needed boundaries of its own. AuthZed sells the permission checks that let ambitious software behave itself.

The plan at Turo was orderly: introduce co-hosting one country at a time. Then somebody deployed it globally. The new permissions system received eight times the expected traffic. According to Turo’s published customer story, SpiceDB handled it. An infrastructure decision had acquired an unusually persuasive reference: an accident.

The permission slip
  • What it does: decides who can access which resource.
  • What you buy: a permissions engine, managed operations or enterprise support.
  • Why it matters: sharing rules become harder as applications, teams and AI agents multiply.

AuthZed, the company behind SpiceDB, works in that unglamorous territory between a useful feature and a dangerous one. Let a colleague edit a document. Let a co-host manage a car. Let an assistant search a company drive. Each invitation sounds simple until somebody asks who else inherits it, when it expires, and what happens after it is revoked.

First, the little function grew teeth

The founders had encountered this problem at Quay, a container registry. Their basic role model soon faced requests for teams, nesting and default permissions. Changes became frightening; some features never shipped. Authorization also consumed too much database CPU. Authentication providers and policy approaches did not resolve their relationship-heavy requirements.

Google’s 2019 Zanzibar paper supplied a different architecture: a centralized service for access decisions across products. AuthZed formed in 2020. Its eventual bet was that permissions deserved their own infrastructure, with their own data model, rather than another anxious patch inside application code.

The founders brought a shared apprenticeship. Jake Moshenko and Joey Schorr met on Google’s APIs team in 2010. They founded Quay; Jimmy Zelinskie became its first hire. Their subsequent work included CoreOS and Red Hat. Today Moshenko is CEO, Schorr CTO and Zelinskie CPO. This is a company whose enthusiasm for infrastructure predates the AI boom.

Jake MoshenkoJoey SchorrJimmy Zelinskie
Three familiar faces, another infrastructure problem. From left: Jake Moshenko, Joey Schorr and Jimmy Zelinskie.

A graph, with manners

Authentication establishes identity. Authorization decides what that identity may do. SpiceDB stores the relationships behind those decisions and evaluates a schema describing the rules. Membership in a team can confer access to a folder; a document can inherit that folder’s permissions. The application asks for a decision through an API.

One possible permission path
Alicesubject
→member
Designteam
→viewer
Briefdocument
CheckPermission(Alice, view, Brief)ALLOW
Office politics, rendered as edges. This illustrative model grants Alice access through her team.

That makes relationship-based access control useful for collaboration, multi-tenant software and delegated work. SpiceDB also supports contextual conditions through Caveats, which Netflix sponsored and helped design. A relationship alone need not settle the matter when the decision also depends on supplied attributes.

There is an essential engineering wrinkle: yesterday’s correct answer can be today’s leak. SpiceDB offers consistency choices and revision tokens so callers can require sufficiently fresh decisions. Those controls need deliberate integration. Buying a permission engine does not absolve an application from knowing when its permissions changed.

The assistant meets the locked drawer

AI retrieval makes that distinction painfully concrete. A search system can find a relevant document without establishing that the person asking may read it. AuthZed’s interactive RAG demonstration retrieves candidates, checks their permissions, then passes only authorized documents to the model. Access is decided before confidential text enters the answer-making machinery.

In AuthZed’s OpenAI customer story, the apps team needed to reproduce permissions from connected services while ingesting enormous document volumes. It considered building its own system, then chose Dedicated. The published account reports more than 37 billion documents processed and a launch serving five million business users. Those figures describe that customer workload, rather than AuthZed’s own audience.

“We decided to buy instead of build early on.”Member of Technical Staff, OpenAI
Quoted in AuthZed’s customer story

Zoom’s story supplies a smaller, revealing threshold. After supporting permissions for two applications, its team recognized the difficulty of scaling its home-built engine. It evaluated alternatives including OpenFGA and selected AuthZed Dedicated. The reported result is permission checks below 50 milliseconds, with less ongoing management effort.

Free engine. Someone still runs it.

SpiceDB is open source under Apache-2.0. AuthZed earns money around it: self-service Cloud, private managed Dedicated deployments, commercially licensed self-hosted Enterprise builds and support. Enterprise adds operational features such as scoped API access and audit logging. Customers choose how much infrastructure responsibility to retain.

Cloud advertises a deployment starting at $2 an hour. At that rate, a continuously running 30-day deployment would cost $1,440. That is arithmetic on an entry price, rather than a production quote. Dedicated capacity is tailored; self-hosted enterprise licensing is annual. Integration, data synchronization and engineering time belong in the purchasing calculation too.

Entry-price arithmetic · not a quote
$1,440 / 30 days
$2 × 24 hours × days · actual configuration varies

The market offers real alternatives. OpenFGA also draws on Zanzibar; Oso Cloud uses its Polar language for application authorization. AuthZed’s case rests on its permissions database, deployment choices and specialist help. A buyer should test those against an actual schema and workload, rather than award points for ancestry.

Compute the answer before the question

In September 2026, Materialize became generally available for Dedicated Cloud. It precomputes expensive portions of the relationship graph and updates the resulting views as relationships change. The point is to avoid repeatedly reconstructing costly answers, especially for large search and AI workloads. It adds a scaling option to the original database thesis.

The business has expanded with restraint. Its June 2024 Series A raised $12 million, led by General Catalyst, bringing announced funding to $15.9 million. AuthZed’s remote-first culture also has a pleasingly human detail: company off-sites prioritize relaxing and bonding before hard decisions and collaboration.

AuthZed colleagues gathered at a company off-site
The humans behind the access rules. AuthZed publishes these gatherings as part of its remote-first working culture.

The practical lesson is portable: model the sharing relationships, test expected grants and denials, and enforce checks wherever data leaves a boundary. For an application with a handful of static roles, a separate service may add more machinery than it saves. For complicated sharing, the invitation to reconsider is simpler: count the features waiting on a permission change.