Skip to content
atif.hossain
Toggle menu
← All work

Authorization at scale

Authorization at scale for a multi-tenant SaaS platform

Sudoblock · 2025

<1ms
permission check
0
manual rule config
3
scope levels unified

The problem

A multi-tenant API-gateway platform needed fine-grained access control across org, project, and resource scopes — without misconfiguration bugs or slow permission checks getting in the way of every request.

The approach

  • Designed a Google Zanzibar-style ReBAC system: a declarative policy language defines role-based access, then compiles down to relation tuples via diff-based reconciliation.
  • Built a code generator that reflects over controller decorator metadata to compile proxy access rules at startup — so rules can never drift from the code they protect.
  • Modeled the org → project → resource scope hierarchy so a single policy expresses access at any level.

The outcome

  • Runtime permission checks resolve in under a millisecond.
  • An entire class of misconfiguration bugs is designed out — rules are generated, not hand-written.
  • Access rules stay in sync with the code automatically, with no manual configuration step.

Stack

TypeScriptNestJSOry KetoOry OathkeeperPostgreSQL

Have a problem like this?

Let’s scope it on a free 20-minute call.