S> initializing
SLAEGA·19
auth-systemapi-webservicepoc-prototype

OpenFGA — Multi-tenant SaaS Authorization

May 20261 min read
OpenFGA — Multi-t…
auth-system
api-webservice
poc-prototype
OpenFGA
ReBAC
Multi-tenant
SaaS
Zanzibar
IAM
Sécurité
MVP
drag

OpenFGA — Multi-tenant SaaS Authorization — MVP

The problem. In a multi-tenant SaaS, one authorization mistake = a data leak between clients. Classic RBAC explodes in complexity as soon as rules become contextual.

What I built (used in Focus Suite)

  • OpenFGA relation-based model: organization, team, resource, permission inheritance.
  • Tenant isolation guaranteed by systematic checks (check(user, relation, object)) on every access.
  • Business roles (owner, admin, member, viewer) expressed as relations, not code — change a rule without redeploying.
  • list-objects queries to show "everything this user can see" without N+1 queries.

What it demonstrates. Fine-grained, traceable, maintainable authorization actually shipped in a product — security as a feature, not a patch.

Stack

OpenFGA · NestJS · PostgreSQL · API-first

MVP — integrated, functional authorization model (Focus Suite).

Technologies

Project stack

OpenFGAReBACMulti-tenantSaaSZanzibarIAMSécuritéMVP

Also explore

Similar projects