Delegation bounded by an amount instead of time: a capped in-game purchase allowance, a category-scoped grocery basket, and why neither is a running total - OpenFGA holds nothing between checks. The same shape turns up again in a minor's graduated account access as they age.
https://tobytes.com/articles/delegation-bounded-by-amount-fga
#auth0 #fga
Running the same OpenFGA model, unchanged, across six industries - and the interesting part isn't that it's reused, it's which primitive gets reused for what. Joint ownership vs a permanent limited role vs an actual delegation, and where flattening them would go wrong.
https://tobytes.com/articles/one-fga-model-twelve-industries
#auth0 #fga #identity
A login and the person behind it aren't the same security principal. Extending the delegated-access model from earlier this year with person/persona/business, and mapping it to real Auth0 sub claims for a personal login versus one federated through a workplace IdP.
https://tobytes.com/articles/separating-people-from-accounts-persona-model
#auth0 #identity #fga
Part three in the delegated access series.
The approval flow: FGA resolves the approver, Auth0 CIBA sends a Guardian push, approval creates a delegation. Also: why CIBA consent does not persist across sessions, and why that's fine.
https://tobytes.com/articles/delegated-access-approval-auth0-ciba
#Auth0 #CIBA #Identity #FGA
You've seen all posts