Authorization assurance, continuously

Prove your application asks the right authorization question.

Heimdall connects authorization intent to runtime evidence—finding missing checks, wrong actions, wrong resources, and tenant-boundary failures before they become incidents.

Out-of-band by design Vendor-neutral evidence Deterministic findings
Evidence inspector Live
FINDING · HMD-2841

Authorization action mismatch

High
Servicebilling-api Environmentproduction RoutePOST /invoices/{id}/refund
01
Runtime operationrefundInvoice completed
Observed
02
Authorization contractExpected invoice.refund
Required
03
OpenFGA decisionObserved invoice.read
Mismatch

Works with the authorization stack you already have

OpenFGACerbosSpiceDBOPACedarCustom RBAC

The missing assurance layer

Your policy engine can be right while your application is wrong.

Authorization systems answer the questions they receive. Heimdall independently verifies that every sensitive operation asked the right question in the first place.

01

Missing check

A sensitive operation completed, but no authorization decision was observed.

DELETE /customers/{id}
02

Wrong action

The application performed a refund after checking only whether the user could read.

invoice.read ≠ invoice.refund
03

Wrong resource

Authorization ran against a workspace while the operation changed an invoice.

workspace:27 ≠ invoice:182
04

Tenant mismatch

An allowed decision crossed the tenant boundary declared by the contract.

acme → globex

Evidence, not guesswork

Every finding shows its work.

Heimdall correlates independent runtime signals into one explainable chain. Select a scenario to see how evidence becomes a finding.

Action mismatch

The application checked read before issuing a refund.

The policy engine correctly allowed the question it received—but that was not the action declared for this operation.

Conclusion Expected invoice.refund, observed invoice.read
1
APPLICATIONrefundInvoice completed
✓
2
CONTRACTinvoice.refund required
✓
3
RUNTIME EVIDENCEOpenFGA checked invoice.read
!
HEIMDALL FINDING AUTHORIZATION_ACTION_MISMATCH High confidence · deterministic

Trust by design

Observe first. Never become the outage.

Heimdall stays outside the critical request path. Applications keep their own policy decision points; Heimdall turns their evidence into continuous assurance.

View deployment model ↓
01

Out-of-band

An unavailable Heimdall never blocks a customer request.

02

Vendor-neutral

Normalize evidence across policy engines, frameworks, and custom authorization.

03

Privacy-preserving

Pseudonymize identifiers before they leave the customer boundary.

04

Deterministic core

Authoritative conclusions come from contracts and evidence—not probabilistic guesses.

Progressive adoption

Start with one service. Keep your authorization architecture.

Instrument application behavior and authorization decisions without moving enforcement into Heimdall.

YOUR APPLICATION Billing API
Runtime operations→
ASSURANCE LAYER Heimdall Correlate · Detect · Explain
Decision evidence←
OpenFGA Cerbos Custom
1

Declare

Define what authorization a sensitive route requires.

2

Observe

Emit operations and decisions asynchronously through the SDK.

3

Verify

Correlate independent evidence and surface actionable drift.

4

Prove

Retain an auditable chain for every conclusion.

Deliberately simple architecture

Built for correctness before complexity.

A modular Java platform, PostgreSQL, and a small set of explicit evidence contracts. No broker, graph database, or search cluster is required to prove the product thesis.

Java 25Spring Boot 4PostgreSQL 16React + TypeScript
CUSTOMER SYSTEMS
Application SDKOperations + health
Authorizer adapterDecisions + diagnostics
↓ Language-neutral protocol
HEIMDALL PLATFORM
IngestionContractsCorrelationDetection
↓ Evidence-backed findings
Investigation UI + APIExplainable findings and audit history

Authorization deserves evidence

Know what was enforced.
Prove what was protected.

Bring continuous authorization assurance to your most sensitive application paths.

Request early access