# Base Layer EP 03: Spencer Kimball on Governance Is the Real Blocker
[Listen now](/content/base-layer/spencer-kimball/index.html)

## Security Teams
Prove who can access what, enforce it instantly, and audit every authorization decision.

### Authorization you can prove and audit
Precise access control with instant, auditable, and compliant permission decisions, when it matters most.

01
### Audit every authorization decision
Every permission check and change is logged with full context. When enterprise customers ask for audit trails or SOC2 evidence, you have answers, and permission structures are defined in a readable schema that security teams can review directly.

02
### Instant revocation
Permission changes take effect immediately with strong consistency guarantees. No background jobs, no eventual consistency. When access is revoked, it is reflected across your entire platform instantly, so stale access never becomes an exposure.

03
### Boundaries enforced at the authorization layer
Guarantee tenant and organizational boundaries independent of how data is stored. Customers can only manage access within their own account, and users cannot access resources outside their tenant.

04
### Answer who-can-access-what
AuthZed's LookupSubjects and LookupResources APIs answer "who can access this resource?" and "what can this user access?" so security and compliance teams can audit permission configurations directly.

> "The average cost of a data breach in the financial services industry is $5.56M for 2025." — IBM, Cost of a Data Breach Report 2025

## Authorization infrastructure built for regulatory scrutiny
Proven consistency guarantees ensure permission changes are enforced immediately, eliminating the security gaps that keep compliance teams busy.

01
### Prove compliance on demand
Every authorization decision is logged with full context. When enterprise customers ask for audit trails or SOC2 evidence, you have answers. Permission structures are defined in a readable schema that security teams can review directly.

02
### Strong consistency, no stale access
No waiting for cron jobs, no eventual-consistency windows. When team membership or sharing changes, the next permission check reflects it. Strong consistency guarantees mean you never grant access that should have been revoked.

03
### Delegated administration with hard boundaries
Your schema defines the maximum permissions any role can have. Customers create roles only from the building blocks you expose, and they can't grant access to other tenants or escalate beyond their boundaries.

## Built for regulated and sensitive environments

### Financial Services and Fintech
Maintain complete visibility into who can access what, when, and why. Information barriers and entitlements update in real time, with every decision logged for regulatory examination.

### Regulated and Enterprise SaaS
Support custom roles, SSO integration, and audit logging that enterprise security reviews require, with SOC2-ready audit trails of every authorization decision.

### Healthcare and Sensitive Data
Model complex hierarchies and least-privilege access across sensitive records, with caveated, time-limited grants that expire automatically and leave a complete audit trail.

### Audit and Governance
Give security and compliance teams direct answers to who-can-access-what, with a readable schema and per-tenant logs they can review without reading application code.

### Assessment
#### Where does your authorization stand?
Evaluate your infrastructure across performance, agility, and risk — get a personalized maturity score with actionable next steps.

[Take the Assessment](/content/assessment/index.html) Takes ~2 minutes

## See what AuthZed can do for your security posture.
Learn how security and compliance teams prove access, enforce it instantly, and audit every decision.
