Capability-based Security Model for Cloud IAM in Tardigrade

I’m the author here. Please check out the post and let me know if you have any feedback.

If you have any questions on the Tardigrade Model vs ACL, I’m happy to share my thoughts.

Would love to spark a discussion around macaroons and capabilty-based IAM, and communicate to the broader tech world why our approach is superior to the ACL model employed by AWS and others.

Let’s #bethecloud,



Twitter convo here: