Skip to content
atif.hossain
Toggle menu
← All writing
·9 minDraft

A declarative ReBAC policy language, and why we compiled it to tuples

This piece is an outline in progress — the structure is here, the full write-up is coming.

Access control that stays in sync with code

Role-based access usually rots: rules are hand-written, drift from the code they protect, and one misconfiguration opens a hole. The goal was access control that can't drift — and resolves fast enough to run on every request.

A declarative policy language

A small declarative language describes role-based access across org, project, and resource scopes. It compiles down to relation tuples — the Google Zanzibar model — via diff-based reconciliation.

Outline in progress. The full piece covers the language design, the reconciliation step, and reflecting over controller metadata to generate proxy rules at startup.

Why compile to tuples

  • Sub-millisecond checks at request time
  • Rules generated from code, so they can't drift
  • One policy expresses access at any scope level

The result

Permission checks under a millisecond, an entire class of misconfiguration bugs designed out, and zero manual rule configuration.

Building something in this space?