Evan Sims

@evansims.com

CTO & Co-Founder @InferaDB.com — the Authorization Database. Previously Okta, Auth0, OpenFGA and Ushahidi.

Wow! I am genuinely so insanely impressed with Vivaldi 8.0. I've tried it off and on over the years, but it never felt quite "right" to me. But they really nailed it with this new release. So well polished, with so many quality of life features. Compact tab spacing is a life saver!

So, bizarre question — does anyone know of any wireless (ideally solar-recharged battery) backup cameras that have CarPlay apps in the US market? Looking to install a backup camera in my fiancés car, but he already has a CarPlay unit. I’d rather avoid hard wiring and adding a HUD just for it.

Everyone seems to remember that Icarus flew too close to the sun, but not that his father also told him not to fly too low and let the sea dampen his wings. We only ever tell half the story: the falling half. Hubris makes a better cautionary tale than mediocrity does.

I always appreciate when Claude resorts to question and exclamation marks in its statements — it's reassuring knowing I'm not the only one deeply confused as to what's going on.

Authentication and authorization alone don't achieve tenant isolation. A user can be fully authenticated, fully authorized for their own tenant — and still access another tenant's resources if isolation isn't enforced at the infrastructure level. This isn't theoretical.

Model Context Protocol (MCP) is becoming the standard for connecting AI agents to enterprise systems. But its authorization model has a fundamental problem.

Only 22% of teams treat AI agents as independent identities. The rest? Shared API keys. That stat comes from the 2026 State of AI Agent Security Report — and it should terrify every CISO reading this.

I don't quite know how Marathon's graphic realism aesthetic fits into enterprise software yet, but I can't help wanting every UI I touch to have it. It's just gorgeous.

Broken access control has been the #1 risk on the OWASP Top 10 for two consecutive releases (2021 and 2025). 100% of applications tested by OWASP researchers had some form of broken access control.

AI agents don't ask for permission twice. They make a decision, call your API, access your data. If your access control drifted out of sync last week, you won't know until it's already happened.

Just shipped the new InferaDB website — really proud of how the developer docs, blog (Dispatch), and changelog turned out. inferadb.com First time working with animating SVG. Love the subtle effect it gives Dispatch posts when they load in and on hover.

BildBildBild

I couldn't sleep last night, so I tinkered around and built a tool I've wanted for a while: a no-fuss code coverage reporter for GitHub Actions. Tools like Codecov are convenient, but I think the added overhead of an external service dependency and secrets is overkill.

"We deploy in eu-west-1" is not a data residency guarantee. A deployment configuration is a policy. A consensus protocol that physically can't replicate data outside a jurisdiction is a guarantee. One satisfies an auditor's question. The other satisfies the follow-up.

Your authorization layer is the only part of your infrastructure you can't verify — and it's making every access decision. You've got observability everywhere. APIs, databases, services — all instrumented. But auth? It's a black box. Outputs "allow" or "deny" and you trust it.

Marathon is the first extraction shooter I've found that doesn't feel like a second job. Spent all weekend playing with my partner and friends. The cyberpunk aesthetic is stunning — combat is tight, and even short sessions feel rewarding. Most fun I've had with the genre!

Zero trust for identity? Check. For devices and networks? Yep. For workloads? Of course. For the authorization layer that actually enforces access decisions? Crickets.

I'm building a little game engine in Metal/Vulkan from scratch with Claude Code (just for fun) and I decided I wanted to integrate a big throw back to my early gamer days — Starsiege Tribes skiing. I can't tell you how overjoyed I was that Claude understood this concept thoroughly.

Bild

Ever wonder what's actually happening inside your authorization system? Traditional setups operate like black boxes: permissions go in, yes/no comes out, and you just hope nothing's been tampered with. We're changing that.

At the beginning of each workday, each player draws 7: three ‘Just Checking In’s, two ‘No Rush On This’s, one ‘Per My Last Email,’ and a legendary: ‘Let Me Know How I Can Help.’ You may play any number of kindness spells this turn.

Love building terminal UIs — it scratches an itch that's hard to define. Coming of age in the 90s hacking scene left an impression on me, I think. This is from @InferaDB CLI's `dev status --interactive` command. It's built using our Rust-native TUI framework inspired by Bubble Tea, called Ferment.

Bild