OpenFGA — Multi-tenant SaaS Authorization — MVP
The problem. In a multi-tenant SaaS, one authorization mistake = a data leak between clients. Classic RBAC explodes in complexity as soon as rules become contextual.
What I built (used in Focus Suite)
- OpenFGA relation-based model:
organization,team,resource, permission inheritance. - Tenant isolation guaranteed by systematic checks (
check(user, relation, object)) on every access. - Business roles (owner, admin, member, viewer) expressed as relations, not code — change a rule without redeploying.
list-objectsqueries to show "everything this user can see" without N+1 queries.
What it demonstrates. Fine-grained, traceable, maintainable authorization actually shipped in a product — security as a feature, not a patch.
Stack
OpenFGA · NestJS · PostgreSQL · API-first
MVP — integrated, functional authorization model (Focus Suite).