29 Sep 2026, 4:00 pm
All Authorization Models Are Beautiful – When They Fit Their Purpose
Dr. Heiko Klarl
CEO, Nexis
Patrick Teichmann
Lead Advisor, KuppingerCole Analysts
Roland Baum
Co-Founder & Managing Partner, Umbrella Associates
What does modern authorization look like? Is RBAC still the right choice? When does ABAC or PBAC make sense? And how do organizations strike the right balance between flexibility, security, and governance?
Inspired by a recent panel discussion, Nexis and Umbrella Associates are bringing this conversation to a live webinar featuring Roland Baum and Dr. Heiko Klarl. The session will be moderated by Patrick Teichmann from KuppingerCole Analysts.
Together, they will explore why there is no universally “good” or “bad” authorization model. From RBAC to PBAC – and everything in between – every approach has its strengths when applied to the right use case.
The discussion brings together two complementary perspectives. Roland Baum shares his extensive experience designing and architecting enterprise authorization models, focusing on scalable, secure, and business-driven authorization. Dr. Heiko Klarl adds the governance perspective – how authorization models can be governed, maintained, reviewed, and continuously adapted throughout their lifecycle.
Join us for an interactive discussion with practical insights, real-world experiences, and an open exchange on what modern authorization means in today’s enterprise environments.
Dr. Heiko Klarl is the CEO of Nexis and a distinguished expert in Identity and Access Management (IAM) with more than 20 years of experience. With a strong background in cybersecurity, Heiko excels in structuring complex projects and leading high-performing teams. His ability to connect business and technology enables him to effectively address customer challenges. Heiko is a regular speaker at conferences and publishes research and articles focused on IAM and cybersecurity.
Roland Baum is Co-Founder and Managing Partner of umbrella.associates GmbH, a boutique consultancy near Frankfurt for digital identities and the protection of critical infrastructure. As a Cyber Security and IT Architect, he brings many years of experience in information security, complex system landscapes, and Zero Trust strategies, with a focus on Identity & Access Management (IAM) and Fine Grained Authorization — expertise he has applied for public sector and enterprise clients.
Following this mission, he is member of the OpenID Foundation’s AuthZEN Working Group, focusing on standardized externalized authorization. Roland holds the CISSP, CISA, and CIDPRO® certifications and speaks regularly on zero trust, externalized authorization, and identity for regulated and enterprize environments.
Patrick Teichmann is Lead Advisor at KuppingerCole Analysts, an independent European analyst firm covering Identity & Access Management and Cyber Security. In his advisory practice, he focuses on Identity and Access Management from a strategic, vendor-independent perspective, connecting the strategic dimension with the solution level to develop fit-for-purpose concepts, including in the area of authorization. Drawing on practical experience with the complexity of large organizations, he views authorization within the broader context of IAM, ensuring it stays aligned with an organization’s broader IAM strategy. Patrick regularly speaks at industry conferences, including KuppingerCole’s European Identity and Cloud Conference (EIC), and moderates panels and discussions on identity and governance topics.