<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"><channel><title>rbac-fs Blog</title><link>https://imchintoo.github.io/rbac-fs/blog/</link><description>Notes on file-based RBAC, multi-tenant architecture, and building rbac-fs in the open.</description><item><title>The first question in every access postmortem</title><link>https://imchintoo.github.io/rbac-fs/blog/the-first-question-in-every-access-postmortem.html</link><guid>https://imchintoo.github.io/rbac-fs/blog/the-first-question-in-every-access-postmortem.html</guid><pubDate>Tue, 25 Aug 2026 00:00:00 GMT</pubDate><description>When an access incident hits, the first question is never &quot;how did the bug happen&quot; — it's &quot;who could do this, and who approved it.&quot; Here's why most teams can't answer that in under an hour, and what changes when the answer is a grep.</description></item><item><title>Can file-based RBAC scope what an AI agent touches?</title><link>https://imchintoo.github.io/rbac-fs/blog/can-file-based-rbac-scope-what-an-ai-agent-touches.html</link><guid>https://imchintoo.github.io/rbac-fs/blog/can-file-based-rbac-scope-what-an-ai-agent-touches.html</guid><pubDate>Mon, 24 Aug 2026 00:00:00 GMT</pubDate><description>2026's agent security data says the dominant failure mode is over-permissioning, not model behavior — here's an honest look at where folder-scoped RBAC actually helps, and where it runs out.</description></item><item><title>Why rbac-fs's live-reload never races its own writes</title><link>https://imchintoo.github.io/rbac-fs/blog/why-rbac-fs-live-reload-never-races-its-own-writes.html</link><guid>https://imchintoo.github.io/rbac-fs/blog/why-rbac-fs-live-reload-never-races-its-own-writes.html</guid><pubDate>Fri, 21 Aug 2026 00:00:00 GMT</pubDate><description>The specific chokidar configuration and cache-invalidation ordering that keep rbac-fs's live-reload from ever serving a role it just wrote itself, or missing an edit from someone else.</description></item><item><title>What a Quarterly Access Review Actually Costs You</title><link>https://imchintoo.github.io/rbac-fs/blog/what-a-quarterly-access-review-actually-costs-you.html</link><guid>https://imchintoo.github.io/rbac-fs/blog/what-a-quarterly-access-review-actually-costs-you.html</guid><pubDate>Wed, 19 Aug 2026 00:00:00 GMT</pubDate><description>SOC 2 doesn't just want you to review access quarterly — it wants evidence for every quarter, and most teams are paying for that in engineering-manager hours nobody budgeted.</description></item><item><title>Signs your RBAC model is about to outgrow itself</title><link>https://imchintoo.github.io/rbac-fs/blog/signs-your-rbac-model-is-about-to-outgrow-itself.html</link><guid>https://imchintoo.github.io/rbac-fs/blog/signs-your-rbac-model-is-about-to-outgrow-itself.html</guid><pubDate>Tue, 18 Aug 2026 00:00:00 GMT</pubDate><description>The concrete symptoms that separate &quot;this needs a condition&quot; from &quot;this needs a relationship graph&quot; — and the honest, incremental path if you're actually in the second category.</description></item><item><title>rbac-fs vs OPA vs Zanzibar-style authorization</title><link>https://imchintoo.github.io/rbac-fs/blog/rbac-fs-vs-opa-vs-zanzibar-style-authorization.html</link><guid>https://imchintoo.github.io/rbac-fs/blog/rbac-fs-vs-opa-vs-zanzibar-style-authorization.html</guid><pubDate>Mon, 17 Aug 2026 00:00:00 GMT</pubDate><description>OPA/Rego and Zanzibar-style engines like OpenFGA and SpiceDB solve real problems rbac-fs doesn't — here's what each actually costs to operate, and an honest line for where rbac-fs stops being the right tool.</description></item><item><title>The Authorization Cost Nobody Is Pricing In</title><link>https://imchintoo.github.io/rbac-fs/blog/the-authorization-cost-nobody-is-pricing-in.html</link><guid>https://imchintoo.github.io/rbac-fs/blog/the-authorization-cost-nobody-is-pricing-in.html</guid><pubDate>Sun, 16 Aug 2026 00:00:00 GMT</pubDate><description>The build-vs-buy literature treats authorization as a choice between building a service and buying one, but the cost data both sides cite actually argues for a third option neither names.</description></item><item><title>Why the permission check has zero dependencies</title><link>https://imchintoo.github.io/rbac-fs/blog/why-the-permission-check-has-zero-dependencies.html</link><guid>https://imchintoo.github.io/rbac-fs/blog/why-the-permission-check-has-zero-dependencies.html</guid><pubDate>Fri, 14 Aug 2026 00:00:00 GMT</pubDate><description>2026's npm supply-chain attacks got names and dates — here's why the code path that decides who's allowed to do what is the worst place to carry that exposure, and what rbac-fs does about it specifically.</description></item><item><title>Permission drift is a solved problem in IaC. Not in RBAC.</title><link>https://imchintoo.github.io/rbac-fs/blog/permission-drift-is-a-solved-problem-in-iac-not-in-rbac.html</link><guid>https://imchintoo.github.io/rbac-fs/blog/permission-drift-is-a-solved-problem-in-iac-not-in-rbac.html</guid><pubDate>Thu, 13 Aug 2026 00:00:00 GMT</pubDate><description>Infrastructure teams spent years naming and tooling against &quot;drift&quot; — the gap between declared and enforced state. Most RBAC systems have the exact same failure mode and no name for it.</description></item><item><title>What a due-diligence checklist finds in your authorization layer</title><link>https://imchintoo.github.io/rbac-fs/blog/what-a-due-diligence-checklist-finds-in-your-authorization-layer.html</link><guid>https://imchintoo.github.io/rbac-fs/blog/what-a-due-diligence-checklist-finds-in-your-authorization-layer.html</guid><pubDate>Wed, 12 Aug 2026 00:00:00 GMT</pubDate><description>SOC 2 auditors and acquisition due-diligence teams both eventually ask who can do what and prove it — here's what they check, and how rbac-fs answers most of it without extra tooling.</description></item><item><title>Why file-based RBAC beats a policy blob</title><link>https://imchintoo.github.io/rbac-fs/blog/why-file-based-rbac-beats-a-policy-blob.html</link><guid>https://imchintoo.github.io/rbac-fs/blog/why-file-based-rbac-beats-a-policy-blob.html</guid><pubDate>Wed, 12 Aug 2026 00:00:00 GMT</pubDate><description>Git-diffable roles aren't a gimmick — they change who can review a permission change, and when, compared to an opaque policy blob in a database.</description></item><item><title>rbac-fs vs Casbin vs CASL</title><link>https://imchintoo.github.io/rbac-fs/blog/rbac-fs-vs-casbin-vs-casl.html</link><guid>https://imchintoo.github.io/rbac-fs/blog/rbac-fs-vs-casbin-vs-casl.html</guid><pubDate>Mon, 10 Aug 2026 00:00:00 GMT</pubDate><description>Three real libraries, three different trade-offs — storage model, framework coverage, and what happens when you need to audit a permission change.</description></item><item><title>Multi-tenant permissions without a database</title><link>https://imchintoo.github.io/rbac-fs/blog/multi-tenant-permissions-without-a-database.html</link><guid>https://imchintoo.github.io/rbac-fs/blog/multi-tenant-permissions-without-a-database.html</guid><pubDate>Sat, 08 Aug 2026 00:00:00 GMT</pubDate><description>Folder isolation instead of a WHERE clause — what that structurally buys you for tenant isolation, and where it stops being enough at real scale.</description></item><item><title>How rbac-fs resolves a permission check</title><link>https://imchintoo.github.io/rbac-fs/blog/how-rbac-fs-resolves-a-permission-check.html</link><guid>https://imchintoo.github.io/rbac-fs/blog/how-rbac-fs-resolves-a-permission-check.html</guid><pubDate>Fri, 07 Aug 2026 00:00:00 GMT</pubDate><description>What actually happens between calling can() and getting true or false back — role loading, inheritance, and condition evaluation, in order.</description></item><item><title>Building your first permission check with rbac-fs</title><link>https://imchintoo.github.io/rbac-fs/blog/building-your-first-permission-check.html</link><guid>https://imchintoo.github.io/rbac-fs/blog/building-your-first-permission-check.html</guid><pubDate>Wed, 05 Aug 2026 00:00:00 GMT</pubDate><description>A tutorial-paced walkthrough of installing rbac-fs, creating a role, and running your first can() check, in both JavaScript and TypeScript.</description></item><item><title>Why roles should change without a redeploy</title><link>https://imchintoo.github.io/rbac-fs/blog/runtime-role-management-no-redeploy.html</link><guid>https://imchintoo.github.io/rbac-fs/blog/runtime-role-management-no-redeploy.html</guid><pubDate>Mon, 03 Aug 2026 00:00:00 GMT</pubDate><description>A permission system that requires a deploy to add one role is solving the wrong problem — how rbac-fs makes role changes a runtime operation instead.</description></item><item><title>Tutorial: create, grant, revoke, delete roles</title><link>https://imchintoo.github.io/rbac-fs/blog/tutorial-create-grant-revoke-delete-roles.html</link><guid>https://imchintoo.github.io/rbac-fs/blog/tutorial-create-grant-revoke-delete-roles.html</guid><pubDate>Sat, 01 Aug 2026 00:00:00 GMT</pubDate><description>A hands-on walkthrough of every dynamic role management call in rbac-fs, with the actual file contents shown at each step.</description></item><item><title>Every allow and deny, logged</title><link>https://imchintoo.github.io/rbac-fs/blog/every-allow-and-deny-logged.html</link><guid>https://imchintoo.github.io/rbac-fs/blog/every-allow-and-deny-logged.html</guid><pubDate>Thu, 30 Jul 2026 00:00:00 GMT</pubDate><description>How rbac-fs's built-in audit trail works — JSONL format, why not a single JSON array, and what's actually in each record.</description></item><item><title>Tutorial: querying and rotating rbac-fs audit logs</title><link>https://imchintoo.github.io/rbac-fs/blog/tutorial-querying-and-rotating-audit-logs.html</link><guid>https://imchintoo.github.io/rbac-fs/blog/tutorial-querying-and-rotating-audit-logs.html</guid><pubDate>Tue, 28 Jul 2026 00:00:00 GMT</pubDate><description>A hands-on walkthrough of configuring log rotation and querying audit history in rbac-fs, including what each rotation option actually controls.</description></item><item><title>Conditional permissions in rbac-fs</title><link>https://imchintoo.github.io/rbac-fs/blog/conditional-permissions-in-rbac-fs.html</link><guid>https://imchintoo.github.io/rbac-fs/blog/conditional-permissions-in-rbac-fs.html</guid><pubDate>Sun, 26 Jul 2026 00:00:00 GMT</pubDate><description>Beyond allow or deny — how rbac-fs's condition system handles &quot;approve your own expense report&quot; without reaching for eval() or a rules engine.</description></item><item><title>Tutorial: building a condition tree with rbac-fs</title><link>https://imchintoo.github.io/rbac-fs/blog/tutorial-building-a-condition-tree.html</link><guid>https://imchintoo.github.io/rbac-fs/blog/tutorial-building-a-condition-tree.html</guid><pubDate>Fri, 24 Jul 2026 00:00:00 GMT</pubDate><description>Step-by-step construction of an AND/OR condition tree in rbac-fs, from a single clause to a nested, real-world approval rule.</description></item><item><title>Tutorial: setting up multi-tenant roles</title><link>https://imchintoo.github.io/rbac-fs/blog/tutorial-setting-up-multi-tenant-roles.html</link><guid>https://imchintoo.github.io/rbac-fs/blog/tutorial-setting-up-multi-tenant-roles.html</guid><pubDate>Wed, 22 Jul 2026 00:00:00 GMT</pubDate><description>A hands-on walkthrough of tenant-scoped and shared roles in rbac-fs, including the path-sanitization behavior you should verify yourself.</description></item><item><title>Hand-editing roles and how live-reload picks it up</title><link>https://imchintoo.github.io/rbac-fs/blog/hand-editing-roles-and-live-reload.html</link><guid>https://imchintoo.github.io/rbac-fs/blog/hand-editing-roles-and-live-reload.html</guid><pubDate>Mon, 20 Jul 2026 00:00:00 GMT</pubDate><description>Role files are cached in memory for speed — here's how rbac-fs's chokidar-backed watcher keeps that cache honest when someone edits a file by hand.</description></item><item><title>Tutorial: hand-editing a role file, live</title><link>https://imchintoo.github.io/rbac-fs/blog/tutorial-hand-editing-and-live-reload.html</link><guid>https://imchintoo.github.io/rbac-fs/blog/tutorial-hand-editing-and-live-reload.html</guid><pubDate>Sat, 18 Jul 2026 00:00:00 GMT</pubDate><description>A step-by-step demo of rbac-fs's live-reload — edit a role JSON file directly and see the permission change without restarting anything.</description></item><item><title>Permissions in the browser, without a filesystem</title><link>https://imchintoo.github.io/rbac-fs/blog/permissions-in-the-browser-without-a-filesystem.html</link><guid>https://imchintoo.github.io/rbac-fs/blog/permissions-in-the-browser-without-a-filesystem.html</guid><pubDate>Thu, 16 Jul 2026 00:00:00 GMT</pubDate><description>rbac-fs's Node core never belongs in a browser bundle — here's how RBACClient gives the frontend the same can() call without any filesystem dependency.</description></item><item><title>Tutorial: RBACClient without a framework</title><link>https://imchintoo.github.io/rbac-fs/blog/tutorial-rbacclient-without-a-framework.html</link><guid>https://imchintoo.github.io/rbac-fs/blog/tutorial-rbacclient-without-a-framework.html</guid><pubDate>Tue, 14 Jul 2026 00:00:00 GMT</pubDate><description>A vanilla-JS walkthrough of RBACClient — useful on its own, and as the mental model underneath every rbac-fs frontend framework adapter.</description></item><item><title>The guardrails you don't have to build yourself</title><link>https://imchintoo.github.io/rbac-fs/blog/guardrails-you-dont-have-to-build-yourself.html</link><guid>https://imchintoo.github.io/rbac-fs/blog/guardrails-you-dont-have-to-build-yourself.html</guid><pubDate>Sun, 12 Jul 2026 00:00:00 GMT</pubDate><description>rbac-fs bakes path sanitization, schema validation, reserved names, and circular-inheritance detection into Core Engine, not left to consumers.</description></item><item><title>Tutorial: verifying the security guardrails</title><link>https://imchintoo.github.io/rbac-fs/blog/tutorial-verifying-security-guardrails.html</link><guid>https://imchintoo.github.io/rbac-fs/blog/tutorial-verifying-security-guardrails.html</guid><pubDate>Fri, 10 Jul 2026 00:00:00 GMT</pubDate><description>Don't take the docs' word for it — four runnable snippets proving path sanitization and circular-inheritance detection actually reject what they claim to.</description></item><item><title>NestJS guards: why unguarded routes fail open</title><link>https://imchintoo.github.io/rbac-fs/blog/nestjs-guards-decorators-and-fail-open-routes.html</link><guid>https://imchintoo.github.io/rbac-fs/blog/nestjs-guards-decorators-and-fail-open-routes.html</guid><pubDate>Wed, 08 Jul 2026 00:00:00 GMT</pubDate><description>rbac-fs's NestJS adapter is opt-in per route via @RequirePermission() — a route with no decorator is allowed through unchecked, deliberately.</description></item><item><title>Tutorial: wiring up the NestJS RbacGuard</title><link>https://imchintoo.github.io/rbac-fs/blog/tutorial-nestjs-rbacguard-walkthrough.html</link><guid>https://imchintoo.github.io/rbac-fs/blog/tutorial-nestjs-rbacguard-walkthrough.html</guid><pubDate>Mon, 06 Jul 2026 00:00:00 GMT</pubDate><description>A runnable walkthrough of rbac-fs's NestJS guard and decorator, driving RbacGuard directly so you can see every outcome without booting a full Nest app.</description></item><item><title>One middleware shape, three Node HTTP frameworks</title><link>https://imchintoo.github.io/rbac-fs/blog/one-middleware-shape-express-koa-fastify.html</link><guid>https://imchintoo.github.io/rbac-fs/blog/one-middleware-shape-express-koa-fastify.html</guid><pubDate>Sat, 04 Jul 2026 00:00:00 GMT</pubDate><description>rbac-fs's Express, Koa, and Fastify adapters share the same rbacMiddleware shape — here's what stays the same and what each framework forces to differ.</description></item><item><title>Tutorial: guarding an Express route with rbac-fs</title><link>https://imchintoo.github.io/rbac-fs/blog/tutorial-express-rbac-middleware.html</link><guid>https://imchintoo.github.io/rbac-fs/blog/tutorial-express-rbac-middleware.html</guid><pubDate>Thu, 02 Jul 2026 00:00:00 GMT</pubDate><description>A runnable, curl-able Express example — one guarded route, three requests, three different outcomes, and the auth-ordering rule that makes it work.</description></item><item><title>Fastify's adapter is a plugin, not middleware</title><link>https://imchintoo.github.io/rbac-fs/blog/why-the-fastify-adapter-is-a-plugin-not-middleware.html</link><guid>https://imchintoo.github.io/rbac-fs/blog/why-the-fastify-adapter-is-a-plugin-not-middleware.html</guid><pubDate>Tue, 30 Jun 2026 00:00:00 GMT</pubDate><description>rbac-fs's Fastify adapter must be registered at the root app, not inside an encapsulated sub-plugin — the encapsulation rule that makes that a hard requirement.</description></item><item><title>Tutorial: the Fastify rbacPlugin end to end</title><link>https://imchintoo.github.io/rbac-fs/blog/tutorial-fastify-rbac-plugin.html</link><guid>https://imchintoo.github.io/rbac-fs/blog/tutorial-fastify-rbac-plugin.html</guid><pubDate>Sun, 28 Jun 2026 00:00:00 GMT</pubDate><description>A runnable Fastify example covering plugin registration, per-route rbac config, and both the allowed and denied response paths.</description></item><item><title>Koa: why rbac-fs reads the user from ctx.state</title><link>https://imchintoo.github.io/rbac-fs/blog/koa-ctx-state-and-async-native-middleware.html</link><guid>https://imchintoo.github.io/rbac-fs/blog/koa-ctx-state-and-async-native-middleware.html</guid><pubDate>Fri, 26 Jun 2026 00:00:00 GMT</pubDate><description>rbac-fs's Koa adapter shares Express's rbacMiddleware signature but reads the user from ctx.state — Koa's own documented convention, not an arbitrary choice.</description></item><item><title>Tutorial: guarding a Koa route with rbac-fs</title><link>https://imchintoo.github.io/rbac-fs/blog/tutorial-koa-rbac-middleware.html</link><guid>https://imchintoo.github.io/rbac-fs/blog/tutorial-koa-rbac-middleware.html</guid><pubDate>Wed, 24 Jun 2026 00:00:00 GMT</pubDate><description>A runnable Koa example — same rbacMiddleware shape as Express, ctx.state instead of req.user, three requests and three outcomes.</description></item><item><title>Declarative permissions in React with &lt;Can&gt;</title><link>https://imchintoo.github.io/rbac-fs/blog/declarative-permissions-in-react-with-can.html</link><guid>https://imchintoo.github.io/rbac-fs/blog/declarative-permissions-in-react-with-can.html</guid><pubDate>Mon, 22 Jun 2026 00:00:00 GMT</pubDate><description>rbac-fs's React adapter follows CASL's I/a naming convention on purpose — one less thing to relearn if your team already knows CASL's mental model.</description></item><item><title>Tutorial: testing React components headlessly</title><link>https://imchintoo.github.io/rbac-fs/blog/tutorial-react-adapter-headless-testing.html</link><guid>https://imchintoo.github.io/rbac-fs/blog/tutorial-react-adapter-headless-testing.html</guid><pubDate>Sat, 20 Jun 2026 00:00:00 GMT</pubDate><description>A headless react-test-renderer walkthrough of &lt;Can&gt;, RbacProvider, and usePermission() — the same technique the adapter's own test suite uses.</description></item><item><title>Vue's v-can directive: why it hides, not unmounts</title><link>https://imchintoo.github.io/rbac-fs/blog/vue-v-can-directive-display-none-vs-unmount.html</link><guid>https://imchintoo.github.io/rbac-fs/blog/vue-v-can-directive-display-none-vs-unmount.html</guid><pubDate>Thu, 18 Jun 2026 00:00:00 GMT</pubDate><description>rbac-fs's v-can directive toggles display:none like v-show — a deliberate choice, different from the true unmount you get from rbac-fs's Angular and React adapters.</description></item><item><title>Tutorial: verifying the Vue adapter headlessly</title><link>https://imchintoo.github.io/rbac-fs/blog/tutorial-vue-adapter-headless-verify.html</link><guid>https://imchintoo.github.io/rbac-fs/blog/tutorial-vue-adapter-headless-verify.html</guid><pubDate>Tue, 16 Jun 2026 00:00:00 GMT</pubDate><description>A runnable, no-browser walkthrough of rbac-fs's Vue plugin, v-can directive, and usePermission() composable using the same verification approach as its test suite.</description></item><item><title>Angular's *rbacCan: real unmount, not hide</title><link>https://imchintoo.github.io/rbac-fs/blog/angular-rbaccan-real-unmount-like-ngif.html</link><guid>https://imchintoo.github.io/rbac-fs/blog/angular-rbaccan-real-unmount-like-ngif.html</guid><pubDate>Sun, 14 Jun 2026 00:00:00 GMT</pubDate><description>rbac-fs's Angular adapter does a real ViewContainerRef unmount/remount, matching *ngIf's own public API instead of a display:none toggle.</description></item><item><title>Tutorial: verifying *rbacCan, no compiler needed</title><link>https://imchintoo.github.io/rbac-fs/blog/tutorial-angular-rbaccan-verify.html</link><guid>https://imchintoo.github.io/rbac-fs/blog/tutorial-angular-rbaccan-verify.html</guid><pubDate>Fri, 12 Jun 2026 00:00:00 GMT</pubDate><description>A runnable walkthrough that drives RbacService and RbacCanDirective directly with a fake ViewContainerRef — the same approach the adapter's own test suite uses.</description></item><item><title>Svelte: explicit stores and actions, not context</title><link>https://imchintoo.github.io/rbac-fs/blog/svelte-stores-and-actions-not-context.html</link><guid>https://imchintoo.github.io/rbac-fs/blog/svelte-stores-and-actions-not-context.html</guid><pubDate>Wed, 10 Jun 2026 00:00:00 GMT</pubDate><description>rbac-fs's Svelte adapter closes over an explicit RBACClient instead of Svelte's context API — favoring traceability over implicit wiring.</description></item><item><title>Tutorial: verifying the Svelte adapter headlessly</title><link>https://imchintoo.github.io/rbac-fs/blog/tutorial-svelte-adapter-headless-verify.html</link><guid>https://imchintoo.github.io/rbac-fs/blog/tutorial-svelte-adapter-headless-verify.html</guid><pubDate>Mon, 08 Jun 2026 00:00:00 GMT</pubDate><description>A runnable, no-browser walkthrough of createPermissionStore and createCanAction — the store and action primitives underneath rbac-fs's Svelte adapter.</description></item></channel></rss>
