Paul Cushing3 Min Read
Designing RBAC That Scales with the Org
A permission model that still makes sense the year after you design it.
3/27/2026
Architecture notes, practical engineering decisions, and lessons learned from production systems.
A permission model that still makes sense the year after you design it.
The boring infrastructure decisions that separate webhooks that work from webhooks that wake you up at 2 AM.
What changes when your prototype stops being a prototype — and how to handle the transition gracefully.
How to ship safely with flags while preventing stale toggles and hidden dead code.
Designing service templates that ship with sane auth, rate limits, and observability from day one.
A step-by-step approach for adding indexes with confidence and validating impact under production load.
Applying DDD concepts in real codebases without over-modeling or process overhead.