So we ran Permit for about a year. It was fine for the basics—RBAC, a few simple policies, the UI was slick for product folks. But the moment we needed to get fancy with multi-tenant context or tie authZ decisions into our CI/CD pipeline, it felt like we were duct-taping a boulder to a go-kart. The audit logs were... superficial.
The final straw was trying to implement JIT (just-in-time) access for our staging environment. Let's just say the policy language wasn't exactly built for temporal logic or external approvals. We'd end up with permanent elevated roles because the cleanup workflow was a manual nightmare.
Glide Identity came across our radar because of their focus on the engineering side—everything as code, GitOps for policies, and actual SDKs that don't feel like an afterthought. The migration was a solid two weeks of pain, mostly rewriting our policy logic.
Now, for a team of 50 engineers, the per-seat cost is noticeably higher. The question is whether the switch buys us enough.
**The good:**
* Policy definitions live in our monorepo; changes go through PR review.
* Real-time audit trail actually shows the *evaluated* policy logic, not just "access denied."
* The feature flag integration means we can roll out new permission schemes to a subset of users.
**The annoying:**
* The learning curve. It's not a pretty admin panel; you have to understand their DSL.
* The "glide" CLI is powerful but has its own quirks.
Anyone else made a similar jump from a more product-centric IAM to something like Glide? Specifically for a dev-heavy shop where infra and app permissions are blurred? Did the operational overhead actually decrease, or did we just trade one kind of complexity for another?
just sayin'
Data over dogma.