Here's the hub for all self-guided AuthZed workshops.
This workshop teaches you to add a deterministic authorization boundary to an agentic RAG system. You'll run a LangGraph-based agentic RAG, watch semantic search leak documents across departments, then implement a SpiceDB permission check the agent can't bypass. Uses SpiceDB, Milvus, LangGraph, OpenAI, and Docker Compose. Link
This workshop teaches you to give AI agents fine-grained, delegated permissions instead of broad ambient credentials. You'll build a DevOps deploy agent on goose and model delegation with SpiceDB using Relationship-Based Access Control (ReBAC) — scoped delegation, time-bound grants that expire on their own, instant revocation, and hierarchical permissions. Uses SpiceDB, goose, Python, and Docker. Link
This workshop gives you hands-on knowledge on using SpiceDB to safeguard sensitive data in your RAG pipelines. There are different branches for this workshop:
- (recommended) Using the OpenAI API, Pinecone, a local Jupyter Notebook instance and SpiceDB. Link
- Using the Deepseek R1 LLM (via OpenRouter), Pinecone, OpenAI Embeddings, a local Jupyter Notebook instance and SpiceDB. Link
This workshop will illustrate how you can update a view based on what permissions the user has. The workshop uses a NextJS template by Vercel for an admin dashboard, written in TypeScript. Link
This workshop teaches you how to build and reason about authorization systems using AuthZed and SpiceDB, powered by Model Context Protocol (MCP) servers. Link
- To update or contribute to a workshop, make a pull request with a detailed description of all changes made.