Already a member?
Access the XACML community workspace here.
The XACML TC focuses on the development of a standard access control policy language. Currently, there are many proprietary or application-specific access control policy languages. This means policies cannot be shared across different applications, and provides little incentive to develop good policy composition and auditing tools.
Many of the existing languages do not support distributed policies, are not extensible, or are not expressive enough to meet new requirements. XACML enables the use of arbitrary attributes in policies, role-based access control, security labels, time/date-based policies, indexable policies, “deny” policies, and dynamic policies–all without requiring changes to the applications that use XACML. Adoption of XACML across vendor and product platforms provides the opportunity for organizations to perform access and access policy audits directly across such systems.
TC Chairs:
Hal Lockhart
Bill Parducci
Staff Contact:
Kelly Cullinane
The main objective of the XACML TC is to define a core XML schema for representing authorization and entitlement policies, along with a standard architecture for enforcing these policies. The TC focuses on making access decisions more flexible, transparent, and interoperable, supporting a wide range of use cases from enterprise security to cloud and distributed computing. XACML helps organizations clearly manage who can access what, when, and under what conditions.
Joining the XACML TC offers the opportunity to shape the future of fine-grained access control standards alongside leading experts in security and policy management. Members gain early insight into emerging specifications, ensure alignment with evolving industry needs, and contribute to open, consensus-based solutions adopted worldwide. It’s a chance to collaborate, influence, and lead in the development of next-generation authorization frameworks.
The XACML TC invites a diverse range of participants interested in shaping the future of access control. This includes:
– Security architects and engineers designing authorization systems
– IAM and cybersecurity vendors building policy-driven tools
– Cloud and SaaS providers needing scalable access control
– Government and compliance experts focused on secure policy enforcement
– Open source developers and researchers advancing access control models
OASIS welcomes interested organizations to join and contribute to the development of an open standards based framework for internationally interoperable lexicographic work. Organizations can participate by becoming OASIS members.
Participation in the XACML TC does not require a significant time commitment. Members typically meet once a month for an hour and collaborate extensively via email and shared documents. If your availability is limited and you prefer not to affect quorum, you have the option to join as an Observer. Observers can stay informed and contribute without the obligation of full participation, though OASIS membership is still required. View more info on committee participation [here].
The XACML TC’s mailing list archive, used by members to conduct Committee work, is available here.
TC membership is required to post to this list. TC members are automatically subscribed.
Whether you want to actively contribute in decision-making or just observe progress from the inside, you will need to be an OASIS member.
If your employer is already on our current member list, submit this request form to be added to the TC Roster. If not, find out how to join OASIS.
Non-members may monitor the mailing list archives online, view approved documents, and provide feedback to our comments list. Contact Us for more information.