Authorisation Architecture
Expert
I design authorisation in three layers from day one: role permissions attached to an organisation membership, OAuth scopes that can only narrow what a client may do, and tenant ownership of every resource. All three are decided in one policy decision point rather than scattered checks.