skip to content

Access Control Models & Enforcement

Role tables, attribute rules and relation tuples, plus the layer the check runs in and how tenancy cuts across it. Interviewers dig here because a missed check is invisible until someone finds it.

on this pageshow

explore

questions

page 2 of 2

When should permissions be copied into an index beside the matters table, and what does the delay between raising a wall and the listing obeying it commit you to?

level: principalimportance: should knowfreq 32%

basics

~20 s

Copy permissions locally when the permitted set is too large to enumerate and the listing is hot. The copy commits you to a written propagation budget, a lag metric, a reconciliation sweep, and removals propagated faster than grants.

open as a page

Should role definitions ship as a seeded catalogue in your codebase, or as rows each district administrator can edit, and what does each commit you to?

level: principalimportance: should knowfreq 42%

basics

~20 s

A seeded catalogue keeps role meanings few, reviewable and changeable in one deploy. Letting organisations compose their own roles turns your permission strings into a published contract you can no longer rename freely, and makes every vocabulary change a data migration across every organisation's rows.

open as a page

How do you migrate airframe sign-off from a role column to relation tuples while both stay authoritative, and what tells you to cut over?

level: principalimportance: should knowfreq 28%

basics

~20 s

Write the schema first, dual-write every grant, backfill history, then shadow-read the tuple check on live traffic while the column still decides. Cut over per relation only after disagreements reach zero across a full business cycle, treating over-grants as security findings.

open as a page

How would you build a roles-by-endpoints permission matrix that a newly added route cannot quietly slip past?

level: principalimportance: should knowfreq 34%

basics

~20 s

Generate the matrix from the server's own route table at test time and cross it with fixture principals. Any route without a declared expectation fails the suite, so a new route is red until a human classifies it, and the declaration file becomes the reviewable statement of policy.

open as a page

showing 31–34 of 34