The day RBAC stops scaling: role explosion and what comes after
Blog post from WorkOS
Role-based access control (RBAC) can become difficult to manage when permissions must apply to individual projects, documents, workspaces, or other resources, leading to “role explosion” as organizations create increasingly specific roles that are no longer reusable. Google’s Zanzibar system addressed this challenge by modeling authorization as relationships among users, groups, and resources, allowing permission checks to traverse ownership, membership, and hierarchy links at request time. WorkOS Fine-Grained Authorization applies a related resource-scoped approach alongside existing RBAC, organizing access around subjects, hierarchical resources, and reusable roles and permissions that can inherit through resource structures. It supports real-time authorization checks, including direct, inherited, and organization-level permissions, while using token-embedded permissions for some broad checks and API calls for resource-specific decisions. Rather than replacing RBAC in a single migration, the proposed approach recommends introducing resource-level controls gradually, running old and new checks in parallel, validating disagreements, and transitioning individual resource types once the new model is reliable.
| Trend | Post Mentions | Total Month Mentions | Posts | Companies | MoM |
|---|---|---|---|---|---|
| Platform Engineering | 1 | 154 | 51 | 23 | -88% |
Use this post, company, and trend context to find content marketing opportunities, perform competitive analysis, or address product feature gaps via the Plushcap MCP server or the Plushcap API.