Phillip Windley

Phil Windley is co-founder and organizer of the Internet Identity Workshop and Executive Director of the IIW Foundation, advancing human-centered digital identity. He was Founding Chair of the Sovrin Foundation (2016–2020) and most recently served as Senior Software Development Manager at AWS Identity.

books by Phillip Windley

Authorization in Action

  • MEAP began September 2025
  • Last updated May 2026
  • Publication in Fall 2026 (estimated)
  • ISBN 9781633435179
  • 400 pages (estimated)
  • printed in black & white

Authorization in Action comes to life through the all-too-real access control struggles facing the fictional ACME Corp’s customer, HR, and engineering systems. Step-by-step walkthroughs make these examples concrete, while real-world incidents—like the Target data breach—show what’s at stake when authorization goes wrong. You’ll implement a dynamic authorization framework integrating the Cedar authorization policy language and the RBAC, ABAC, and ReBAC models, and you’ll design adaptive policies that reflect real business rules. Plus, you’ll build governance structures with clear ownership, aligned teams, and processes to review, audit, and evolve at scale.