When regulators ask you to "prove it," IdP logs only get you partway. They show that someone authenticated. They do not show why that person was allowed to export an invoice, approve a payout, or read another tenant's data.
That proof maps to a runtime architecture:
- PEP — enforce the decision in the app/API/gateway
- PDP — evaluate policy close to the app (hybrid/local beats remote-only on the hot path)
- Decision logs — subject, action, resource, context, allow/deny, and reason
OPAL keeps local PDPs current when membership, roles, or relationships change — without redeploying every service.
I work on this at Permit.io. The full write-up walks through the flow with a concrete invoice-export example.
Top comments (0)