Skip to content

05 — Identity & Authorisation

Multi-tenant Auth & Access

Single sign-on, tenant isolation, and permissions that admins configure instead of developers hard-coding.

Authentication and authorisation for a multi-product platform. Each customer gets an isolated tenant, users sign in through enterprise SSO, and what they can do is decided by policy rather than by conditionals scattered through the code.

Built as a shared service so several products could adopt it without each reinventing login.

What I built

  • 01Single sign-on with enterprise identity providers and automatic tenant discovery
  • 02Service-to-service authentication over OAuth2 client credentials
  • 03A closed privilege catalogue — permissions composed by admins, not invented per route
  • 04Tenant isolation enforced at the query layer, not just the API surface
  • 05Real-time permission updates pushed to connected clients
  • 06Session handling, refresh flows and secure cookie management

Outcomes

  • —One auth layer adopted across multiple products
  • —Role changes became configuration instead of a deployment
  • —Credential and sensitive-data leakage removed from service logs