- From: Will Abramson (W3C Calendar) <noreply+calendar@w3.org>
- Date: Mon, 26 Jan 2026 14:31:07 +0000
- To: Credentials Community Group <public-credentials@w3.org>
- Message-ID: <edc1eb7ab0dfc1b948f047671538a65f@w3.org>
[View this event in your browser](https://www.w3.org/events/meetings/6c106024-7f5f-4297-972b-18af6432aaef/20260127T120000/) W3C CCG - Use Cases for Access Management Upcoming Confirmed ============================================================= 27 January 2026, 12:00 -12:50 America/New\_York Event is recurring Weekly on Tuesday, starting from 2 September 2025, until 30 June 2026 [ Credentials Community Group ](https://www.w3.org/groups/cg/credentials/calendar/)Alan Karp on Use Cases for Access Management. This talk argues that many identity and access management (IAM) failures come from starting with the wrong use cases and ignoring the hazards that emerge as systems grow more complex. Drawing on three decades of experience—from early large‑scale access control deployments to work with the US Navy and modern systems like AWS Cedar and Solid—it shows how designs focused on simple ACL-style scenarios bake in vulnerabilities, complexity, and usability problems. Using a progression of concrete use cases, the talk surfaces hazards such as excess authority, weak delegation, missing responsibility tracking, awkward conditional policies, and transitive access issues, then demonstrates how authorization‑centric models and capability-style approaches address them more naturally than traditional authentication‑centric IAM. Attendees will leave with a sharper vocabulary for IAM “use case hazards” and a set of design principles for building systems that handle delegation, composition, and accountability without bolting on fixes after the fact. Meeting Link: <https://meet.google.com/dzc-yjfq-tyf> Agenda ------ Agenda: 1. Code of Ethics & Professional Conduct Reminder: <https://www.w3.org/Consortium/cepc/> 2. IP Note: a. Anyone can participate in these calls. However, all substantive contributors to any CCG Work Items must be members of the CCG with full IPR agreements signed. <https://www.w3.org/community/credentials/join> b. Ensure you have a W3 account: <https://www.w3.org/accounts/request> c. W3C Community Contributor License Agreement (CLA): <https://www.w3.org/community/about/agreements/cla/> 3. Call Notes are shared with the W3C mailing list within 24 hours 4. Introductions & Reintroductions 5. Announcements & Reminders: <https://w3c-ccg.github.io/announcements/> 6. Work Items: <https://github.com/w3c-ccg/community/issues?q=is%3Aopen+is%3Aissue+label%3A%22action%3A+review+next%22> 7. Main Agenda 8. Discussions Joining Instructions -------------------- [ Join the meeting ](https://meet.google.com/dzc-yjfq-tyf)Google Meet: <https://meet.google.com/dzc-yjfq-tyf> Voice: Dial: (US) +1 434-265-5260 PIN: 242 728 140# More phone numbers: <https://tel.meet/dzc-yjfq-tyf?pin=8764998681084> Participants ------------ ### Organizers - Will Abramson - Mahmoud Alkhraishi - Harrison Tang ### Groups - [Credentials Community Group](https://www.w3.org/groups/cg/credentials/) ([View Calendar](https://www.w3.org/groups/cg/credentials/calendar/)) ### Invitees - Somaya Assaker - Otto Mora Report feedback and issues on [ GitHub](https://github.com/w3c/calendar "W3C Calendar GitHub repository"). To stop receiving these emails please update [your calendar preferences](https://www.w3.org/users/myprofile/calendar/preferences/).
Attachments
- text/calendar attachment: event.ics
Received on Monday, 26 January 2026 14:32:16 UTC