← Back to experience
Case study · Okta · 2025 - 2026
Moving the Demo Platform to fine-grained authorization
Replaced hard-coded permission checks in the Demo Platform with a relationship-based model on Auth0 FGA, and proved it matched the old checks on live traffic before switching it on.
- 600+
- live decisions shadow-compared
- 100%
- match with legacy checks
- 8
- endpoints moved
Problem
Lab management permissions in the Demo Platform were enforced by legacy checks spread across endpoints. Changing who could do what meant changing code in several places.
My role
I wrote the PRD and the relationship-based authorization model, built the Node.js integration, and ran the rollout.
Approach
- Modelled users, labs and roles as relationships in Auth0 FGA.
- Wrote FGA tuples behind a feature flag, so the new data could build up without affecting users.
- Ran FGA checks in shadow mode next to the legacy checks on live traffic and compared every decision.
- Moved the 8 endpoints over once the comparison showed no differences.
Result
600+ live decisions matched the legacy checks at 100%. FGA is now enforced in production for Demo Platform lab management.
Auth0 FGANode.jsTypeScriptAWS LambdaDynamoDBFlagsmith