← All work
Authorization at scale
Authorization at scale for a multi-tenant SaaS platform
Sudoblock · 2025
<1ms
permission check
0
manual rule config
3
scope levels unified
The problem
A multi-tenant API-gateway platform needed fine-grained access control across org, project, and resource scopes — without misconfiguration bugs or slow permission checks getting in the way of every request.
The approach
- Designed a Google Zanzibar-style ReBAC system: a declarative policy language defines role-based access, then compiles down to relation tuples via diff-based reconciliation.
- Built a code generator that reflects over controller decorator metadata to compile proxy access rules at startup — so rules can never drift from the code they protect.
- Modeled the org → project → resource scope hierarchy so a single policy expresses access at any level.
The outcome
- Runtime permission checks resolve in under a millisecond.
- An entire class of misconfiguration bugs is designed out — rules are generated, not hand-written.
- Access rules stay in sync with the code automatically, with no manual configuration step.
Stack
TypeScriptNestJSOry KetoOry OathkeeperPostgreSQL