Tim Hinrichs
- Co-created Open Policy Agent with Torin Sandall and Teemu Koponen
- Co-founded Styra and served as its CTO
- OPA is a graduated CNCF project
Bio
Tim Hinrichs co-created Open Policy Agent with Torin Sandall and Teemu Koponen, and co-founded Styra, where he was CTO. OPA entered the CNCF sandbox in 2018 and is now a graduated project.
Profile built from public project, foundation, and company records.
Where their work shows up
OPA made a specific argument that stuck: authorization should be a decision a general-purpose policy engine makes from declarative rules, not a pile of conditionals scattered through application code. Rego is the language for those rules, and the same engine now decides Kubernetes admission, API authorization, and infrastructure policy. See RBAC vs ABAC vs ReBAC, the Styra and OPA profile, and the best authorization tools ranking.
Related on Start with Identity
- BlogAgent identity just got a protocol, which is the easy half
Okta shipped Agent SSO and got Cross App Access adopted into MCP the same month a GitHub issue was shown to reach CI secrets in Claude Code and Gemini CLI. The
- BlogAgentic AI Identity Is the Next Frontier (And Your IAM Stack Isn't Ready)
AI agents now act on behalf of users, call APIs, and chain tools together. They need identities, scopes, and audit trails, and almost no existing IAM stack was
- BlogCrowdStrike agrees to buy SGNL for 740 million dollars
The deal that opened 2026's consolidation wave. SGNL brings CAEP-based continuous access evaluation and just-in-time authorization to a Falcon identity business
- CVEKeycloak authorization bypass
Keycloak failed an authorization check, so a caller could reach a resource their role should have blocked. Part of the April 2024 RHSA-2024:1868 set with CVE-20
- CVEKeycloak UMA policy privilege escalation
Keycloak's UMA policy engine checked only the first resource in a request (CWE-266). Additional resources skipped the check. A privilege escalation in user-mana
- CVESailPoint IdentityIQ role-editing authorization flaw
IdentityIQ failed to authorize role edits on all versions at disclosure (April 2026). Anyone who could reach the role-editing surface could change roles they sh