At wroclove.rb 2025, Yatish Mehta (Asana) surveys Rails authorization approaches — implicit scopes, CanCan, Pundit — and their scaling problems, then introduces Fine-Grained Authorization (FGA / ReBAC) based on Google's Zanzibar. He presents his gem granity, which brings relationship-based access control with schema, tuples, smart caching, reverse lookups and audit paths to Rails apps, with Q&A on modeling sensitive tasks and syncing relationships.
claude-opus-4-7623af82e