Hi everyone! I've been lurking for a while, learning a ton from you all. So, first of all, thanks! 🙏
I'm currently trying to design the authz layer for a new set of internal data pipelines (Airflow + Snowflake, mostly). The auth part (SSO) is handled, but now I need to implement fine-grained permissions *within* the application. Think: "Can this data scientist group run this specific DAG?" or "Can this analyst group query *this* particular table in Snowflake via our tool?"
My research keeps pointing me towards two main options: **Glide Identity** and **Permit.io**. They both seem to pop up a lot in conversations about externalized authorization.
I'm feeling a bit overwhelmed trying to choose, and I'd love to hear from anyone who has practical experience with either (or both!) in a data/analytics context.
Some specific things I'm trying to figure out:
* **Language/SDK Fit:** Our backend services are Python-heavy. How's the developer experience for integrating these checks into a FastAPI app?
* **Policy Management:** The idea of a centralized policy dashboard is appealing. Which one feels less "over-engineered" for a team that's not full-time security experts?
* **Data Context:** Can they easily handle permission checks that need to consider *attributes* of the data itself? Or is that something we'd still have to mostly handle in our own code?
* **Learning Curve:** As a relative newcomer to this specific IAM/PAM depth, which one might have clearer docs or a more gradual onboarding?
I've already hit a wall trying to roll my own RBAC, so I'm really hoping to adopt a proper solution this time. Any stories, warnings, or "I wish I knew" moments would be incredibly helpful.
null