After evaluating alternatives, including a bespoke authorization platform and OpenFGA, Zoom’s agentic search team chose AuthZed Dedicated to provide a single, scalable platform for permissions management.
Zoom’s agentic search is an enterprise-grade knowledge retrieval layer that gathers, indexes, and synthesizes relevant information across Zoom-native content and authorized third-party data sources.
Building a context layer for agentic search is inherently challenging: it must bring together data from many third-party sources, each governed by its own permissions and access-control system. As the team began ingesting this data alongside Zoom’s own, a shared, centralized permission engine became essential for determining—consistently and at scale—whether a user could access a specific resource.
Without a shared, centralized permission engine, safely unifying data from many third-party sources—each governed by its own permissions and access-control system—was a major blocker for Zoom’s agentic search team. Initially, the team tried to build their own authorization system.
That complexity, and the need to maintain a growing system at increasing scale, pushed the team to research alternative approaches.
Initially, we tried to build our own authorization system. We quickly learned that building a permission engine is difficult, time-consuming, and resource-intensive. It requires deep subject-matter expertise across identity, access control, data modeling, and the different permission models used by each application. Even after supporting permissions for two applications, it became clear that continuing to build and maintain the system ourselves would be difficult to scale. We needed to have a more sophisticated platform to ingest more applications.
Yanming Tang, Engineering Manager, Zoom
After reading the Zanzibar paper, the agentic search team decided the relationship-based access control (ReBAC) approach it describes fit their needs.
ReBAC was the most ideal solution that solves for many different scenarios, so it became a no-brainer choice as a starting point.
Yanming Tang, Engineering Manager, Zoom
After weighing options, Zoom selected AuthZed for three reasons:
AuthZed’s underlying permission datastore can scale horizontally as customer volume, data sources, and authorization checks grow. This gives Zoom a clear path to onboard large customers without requiring a fundamental redesign of its permissions system.
“AuthZed stood out for its depth of technical understanding. Its annotated version of the Zanzibar paper demonstrated a serious engagement with the architectural challenges of building authorization systems that are consistent, low-latency, highly available, and scalable. AuthZed also supported its approach with detailed performance methodology and published results. This combination of technical depth and measurable performance gave us confidence in AuthZed’s maturity as an authorization platform.”
“AuthZed was there whenever we needed support. The team helped us optimize performance, scale the system, and develop better solutions quickly. The dedicated schema review was especially valuable because once the schema and framework are in place, the remaining development work becomes much simpler.”
AuthZed now powers core permission checks for third-party data in Zoom’s agentic search pipeline, delivering sub-50ms checks at intense scale and meeting Zoom’s performance requirements. Beyond speed, the permissions system has been a major operational win for Engineering, simplifying and streamlining access management.
AuthZed simplifies our permissions management effort and makes managing various third-party permissions so much easier. AuthZed significantly simplifies our permissions management effort and reduces ongoing operational overhead.
Yanming Tang, Engineering Manager, Zoom
Tang also noted that reduced management burden means faster time-to-ship on new integrations. With the schema already in place, adding permission logic for a new application integration is now “basically a no-brainer.”
Core permission checks for third-party data at intense scale, meeting Zoom’s performance requirements
A single, centralized platform for managing permissions across many authorized data sources
Less ongoing effort for Engineering to manage permissions as the platform grows
With the schema already in place, adding permission logic for a new application integration is now basically a no-brainer