

Industries · Government
Public sector systems carry citizen data, change staff with the season, and answer to auditors and to the public. Permit gives every employee, contractor, and service exactly the access their task requires, and keeps a record of every decision.

“Permit allowed us to increase security and process automation for millions of Maricopa County voters”
Nate YoungChief Information Officer, Maricopa County Recorder’s OfficeElection workers, seasonal staff, and contractors need access for weeks, scoped to specific tasks, and that access has to disappear when the work does.
When every permission change needs a developer or a ticket, access requests pile up exactly when the mission is busiest.
Agencies and their contractors run many programs with different teams and data, and every one still has to meet the same security requirements.
Least privilege must be shown to auditors and oversight bodies, not only described in a policy document.
Fine-grained policy that program staff can administer and security teams can trust, deployed where your data is required to live.
Decide on role, department, assignment, location, and time window, so temporary staff reach only the functions their task needs.
Department managers adjust access through a no-code interface inside boundaries IT sets. Maricopa County’s Recorder’s Office moved permission management out of the IT queue this way.
Permit is the policy decision point in NIST SP 800-207 terms. Your gateways and services are the enforcement points, and they ask before every request.
Run decision points in your network, or self-host the whole platform, control plane included, on infrastructure you operate.
Every decision is recorded, so IT monitors access instead of writing and maintaining permission code.
A seasonal worker’s access, checked against assignment and time window. Illustrative data.

Hybrid deployment
Permit control plane
Permit cloud, or self-hosted
Your network
VPC, data center, or on-prem
Policy decision points
Run beside your services and gateways. Decisions keep working from cached policy.
NIST guidance separates deciding access from enforcing it, and expects both to be auditable. That separation is exactly how Permit is built.
| Framework | What it asks for | How Permit helps |
|---|---|---|
| NIST SP 800-53 Rev. 5, AC-3 | Enforce approved authorizations for logical access to information and system resources. | Permit’s decision point evaluates each request against approved policy, and your services enforce the answer. |
| NIST SP 800-53 Rev. 5, AC-6 | Allow only the access users and processes need to accomplish assigned tasks. | Attribute and relationship policies grant task-scoped access instead of broad standing roles. |
| NIST SP 800-53 Rev. 5, AU-2 and AU-12 | Define which events are logged, and generate records for them. | Each authorization decision produces a log entry with the policy that applied and the reason. |
| NIST SP 800-207, Zero Trust Architecture | Access decided per request by a policy decision point and enforced by a policy enforcement point. | Permit is the policy decision point. Your applications, gateways, and APIs call it and enforce the answer. |
Framework summaries are paraphrased for orientation and are not legal advice. No authorization vendor makes you compliant on its own. Permit helps you implement and evidence the access controls these frameworks test; your audits remain your own. Permit is not FedRAMP authorized. Where systems must stay inside your own boundary, Permit can be fully self-hosted.
“Permit gives us the power and flexibility we need to manage complex permissions configuration across hundreds of projects, while maintaining the high level of security needed by our clients at the US Department of Energy. I highly recommend this technology for anyone who doesn't want to waste time reinventing the wheel on authorization.”
Craig HaselerProject Manager, TechSource Inc, Contractor to the US Department of EnergyYes. In hybrid deployments, decision points run in your network. In full on-premises deployments, the control plane runs there too, packaged as a Helm chart and compatible with OpenShift.
No. Permit’s cloud service holds a SOC 2 Type II attestation. Organizations that need systems inside their own boundary can run Permit fully self-hosted.
Grant access through attributes such as assignment and time window, instead of creating accounts with broad roles. When the assignment ends, the policy stops allowing the access.
Yes. Managers work in a no-code interface, inside guardrails set by IT that control which roles and resources they may change. Every change and decision is logged.
Permit acts as the policy decision point described in NIST SP 800-207. Your services and gateways act as enforcement points, asking Permit before allowing each request.
Tell us what you are authorizing and where it runs. We come to the call with a model of how Permit would enforce it.