Why authorization architecture is probably fragile
We initially built our own authorization system in PostgreSQL, but as requirements grew more complex, we had to evolve toward a relation-based authorization service. We chose SpiceDB to handle advanced use cases like organizational hierarchies and temporary access. However, while solving many technical challenges, it also opened up new security risks, particularly around ensuring consistent and…
