I don't know. This seems to be something I’d get a slap on the hand from our security team. No chance ever they give away the power they have for control who have permission. Just me??
I think this should not be a problem with the proper compliance certifications (SOC 2, PCI, etc.). Similar logic applies to Auth0 and even using cloud computing, for that matter.
Hi there! I appreciate the concern - But note that Permit elements allow you to delegate access control to any one of your team members, end users, or customers - as it uses a simple no-code UI to do that, It could allow your security team easier access to overview the entire process, and thanks to Permit.io building on policy as code you always have full control of the generated flow via Git.