DEV Community

Auth By Example
Auth By Example

Posted on

Login events are not authorization evidence

When regulators ask you to "prove it," IdP logs only get you partway. They show that someone authenticated. They do not show why that person was allowed to export an invoice, approve a payout, or read another tenant's data.

That proof maps to a runtime architecture:

  1. PEP — enforce the decision in the app/API/gateway
  2. PDP — evaluate policy close to the app (hybrid/local beats remote-only on the hot path)
  3. Decision logs — subject, action, resource, context, allow/deny, and reason

OPAL keeps local PDPs current when membership, roles, or relationships change — without redeploying every service.

I work on this at Permit.io. The full write-up walks through the flow with a concrete invoice-export example.

Top comments (0)