Torin Sandall
- Co-created Open Policy Agent and led its open-source engineering
- Drove OPA from CNCF sandbox in 2018 to graduated project
Bio
Torin Sandall co-created Open Policy Agent and led its open-source work as VP of open source at Styra, taking the project from the CNCF sandbox in 2018 through to graduation.
Profile built from public project, foundation, and company records.
Where their work shows up
Graduating a CNCF project is a governance achievement as much as a technical one: it means adoption, a contributor base beyond the founding company, and a security process that does not depend on one vendor staying solvent. That matters for authorization specifically, because a policy engine is the kind of dependency an organization cannot casually replace. See the authorization vendors, implementing ABAC, and the best authorization tools ranking.
Related on Start with Identity
- BlogAgent identity just got a protocol, which is the easy half
Okta shipped Agent SSO and got Cross App Access adopted into MCP the same month a GitHub issue was shown to reach CI secrets in Claude Code and Gemini CLI. The
- BlogAgentic AI Identity Is the Next Frontier (And Your IAM Stack Isn't Ready)
AI agents now act on behalf of users, call APIs, and chain tools together. They need identities, scopes, and audit trails, and almost no existing IAM stack was
- BlogCrowdStrike agrees to buy SGNL for 740 million dollars
The deal that opened 2026's consolidation wave. SGNL brings CAEP-based continuous access evaluation and just-in-time authorization to a Falcon identity business
- CVEKeycloak authorization bypass
Keycloak failed an authorization check, so a caller could reach a resource their role should have blocked. Part of the April 2024 RHSA-2024:1868 set with CVE-20
- CVEKeycloak UMA policy privilege escalation
Keycloak's UMA policy engine checked only the first resource in a request (CWE-266). Additional resources skipped the check. A privilege escalation in user-mana
- CVESailPoint IdentityIQ role-editing authorization flaw
IdentityIQ failed to authorize role edits on all versions at disclosure (April 2026). Anyone who could reach the role-editing surface could change roles they sh