One permissions layer. Every app on the platform. Zero copies of the rules. Last week I showed yo...One permissions layer. Every app on the platform. Zero copies of the rules. Last week I showed yo...
The network for creativity
Join 1.25M professional creatives like you
Connect with clients, get discovered, and run your business 100% commission-free
Creatives on Contra have earned over $150M and we are just getting started
One permissions layer. Every app on the platform. Zero copies of the rules.
Last week I showed you Funding — one app on the Own the Podium platform. The part I'm proudest of isn't inside it.
Roles and permissions don't live in Funding, or Performance, or User Management. They live in one shared layer underneath all of them. Every app asks the same question the same way — can this role take this action at this stage? — and none of them keeps its own copy of the rules.
What that buys you: a new app means registering its actions, not rebuilding auth. Switching a role on for Funding and off for Performance is a toggle, not a deploy. And there's one audit trail, because there's only one place an action can be permitted.
The front ends are independent micro-frontends; the permissions layer is what makes them behave like one product.
Someone in the comments last week called it decoupling permissions from static roles. I'd go one further: decouple them from the app, too.
Back to feed
The network for creativity
Join 1.25M professional creatives like you
Connect with clients, get discovered, and run your business 100% commission-free
Creatives on Contra have earned over $150M and we are just getting started