Can We Fix Broken Authorization in APIs Without Giving Up Microservices' Agility?
Microservices are loosely-coupled by design but least-privilege security requires a tight coupling of state and policy across all services