Zero-database · File-based · Multi-tenant
Roles and permissions live as human-readable JSON files under .rbac/ — no database, no opaque policy blob. Every change is a normal, reviewable diff in your PR.
Roles are JSON on disk — every permission change is a normal git diff, not an opaque policy blob.
Tenant separation is structural, not a WHERE clause you can forget.
Full read/write core on the server; a synchronous, read-only snapshot client in the browser.
NestJS, Express, Fastify, Koa, React, Vue, Angular, Svelte — thin, zero duplicated logic.
Every adapter is a thin subpath export — none re-implement permission logic, all call straight into RBAC.can().