Home / Companies / WorkOS / Blog / Post Details
Content Deep Dive

The day RBAC stops scaling: role explosion and what comes after

Blog post from WorkOS

Post Details
Company
Date Published
Author
Zack Proser
Word Count
1,518
Company Posts That Month
32
Language
English
Hacker News Points
-
Post removed?
No
Summary

Role-based access control (RBAC) can become difficult to manage when permissions must apply to individual projects, documents, workspaces, or other resources, leading to “role explosion” as organizations create increasingly specific roles that are no longer reusable. Google’s Zanzibar system addressed this challenge by modeling authorization as relationships among users, groups, and resources, allowing permission checks to traverse ownership, membership, and hierarchy links at request time. WorkOS Fine-Grained Authorization applies a related resource-scoped approach alongside existing RBAC, organizing access around subjects, hierarchical resources, and reusable roles and permissions that can inherit through resource structures. It supports real-time authorization checks, including direct, inherited, and organization-level permissions, while using token-embedded permissions for some broad checks and API calls for resource-specific decisions. Rather than replacing RBAC in a single migration, the proposed approach recommends introducing resource-level controls gradually, running old and new checks in parallel, validating disagreements, and transitioning individual resource types once the new model is reliable.

Trends Found in this Post
Trend Post Mentions Total Month Mentions Posts Companies MoM
Platform Engineering 1 154 51 23 -88%
Use This Data

Use this post, company, and trend context to find content marketing opportunities, perform competitive analysis, or address product feature gaps via the Plushcap MCP server or the Plushcap API.