Policy-based Authorization Manager (PBAM)

Enforce fine-grained authorization across APIs, applications, and data

Define access once. Enforce it everywhere.

Traditional authorization breaks at scale. Roles become unmanageable, policies are scattered, and access decisions are inconsistent. Policy-based Authorization Manager (PBAM) centralizes authorization and enforces it dynamically, at the level that actually matters: the resource and the data.

What is Policy-based Authorization Manager (PBAM)?

Authentication proves who a user is.

Authorization determines what they can do.

If authorization is inconsistent, overly broad, or embedded in code, identity alone does not protect your systems.

Thales Policy-based Authorization Manager (PBAM) is a centralized authorization layer that enables fine-grained, policy-driven access control across your entire architecture.

It separates what access should be allowed from how applications are built.

Access decisions are:

  • Defined through policies
  • Evaluated in real time
  • Enforced consistently across APIs, microservices, and data platforms

PBAM complements your existing IAM and CIAM systems and governs what happens after authentication.

PBAM ensures that access decisions are:

  • Precise
  • Consistent
  • Enforceable
  • Auditable
PBAM diagram

Key Capabilities

Policy-based access control (PBAC)

Policy-based authorization control (PBAC)

Define access using subject, resource, and condition-based policies

Attribute and relationship-based decisions

Attribute and relationship-based decisions

Combine ABAC and ReBAC models for precise control

Fine-grained data protection

Fine-grained data protection

Enforce access at row, column, and field level

Policy-as-code

Policy-as-code

Integrate with CI/CD pipelines

Audit-ready decisions

Audit-ready decisions

Generate traceable, business-readable access decisions

Zero standing privilege

Zero standing privilege

Grant access dynamically based on real-time context

How PBAM works

PBAM is built on three core components:

    Centralized policy definition

    Define access policies using business logic, not application code. Policies express who can access what, and under which conditions.

    Real-time policy evaluation

    Every access request is evaluated at runtime using identity attributes, resource attributes, and contextual signals.

    Distributed enforcement

    Policies are enforced across:

    • APIs
    • applications
    • microservices
    • data services

    No authorization logic resides inside the application. Enforcement happens where access occurs.

    The Problem with Authorization

    Most organizations still rely on:

    • Static role-based access control (RBAC), which cannot express real-world relationships or conditions
    • Embedded authorization logic, tightly coupled to applications
    • API-layer enforcement, which stops short of protecting the underlying data

    This creates structural issues:

    • Access is too broad or inconsistent
    • Changes require application updates instead of policy updates
    • Data remains exposed beyond intended boundaries
    • Audit trails are incomplete or fragmented

    You don’t have an authorization model. You have authorization logic scattered across systems.

    What makes PBAM different

    Resource-level authorization

    Most solutions stop at the API. PBAM enforces access at the actual resource level, such as a transaction, record, or data field.

    No role explosion

    RBAC creates complexity as systems scale. PBAM replaces static roles with dynamic policies that reflect real business logic.

    Consistent enforcement

    Policies are defined once and applied everywhere. No duplication. No drift between systems.

    Built for change

    Policy updates do not require application changes. Access evolves at the speed of business, not development cycles.

    Thales Policy-Based Authorization Manager

    PBAM for OneWelcome Identity Platform

    Enable dynamic authorization with PBAC using Thales PBAM in the OneWelcome Identity Platform for fine-grained, auditable access control.

    PBAM for OneWelcome Identity Platform

    Where PBAM delivers value

      Move beyond endpoint protection. Enforce access decisions at the level of the resource behind the API.

      Control who can see which data, down to row, column, or field level, at query time.

      Manage access across suppliers, distributors, and partners without over-provisioning permissions.

      Demonstrate control with auditable, policy-driven access aligned with regulatory requirements.