Skip to content
All articles
Product1 December 2025·3 min read

FGA : How Paycux is rethinking authorization for the next generation of SaaS

Shipping is the easy half.

Paycux engineering

Shipping is the easy half. The hard half is deciding what the thing is supposed to do for someone who has never read your roadmap and does not care about your architecture.

This piece walks through how we think about it at Paycux, what we have changed our minds about, and where the sharp edges are.

The natural growth pattern of a B2B SaaS product

The natural growth pattern of a B2B SaaS product deserves its own treatment. Defaults are the product. Most people will never open the settings screen, which means the behaviour you chose for them is the behaviour they will experience forever.

Defaults are the product. Most people will never open the settings screen, which means the behaviour you chose for them is the behaviour they will experience forever.

Every new feature forces the model to evolve

Every new feature forces the model to evolve is where this gets concrete. Naming is design work. If the team argues about what to call something, the disagreement is usually about what it is, and shipping before that is settled means shipping the confusion to customers.

Ship the smallest version that is honest about its limits. A feature that does one thing completely beats one that does five things with an asterisk on each.

  • Choose defaults as carefully as features
  • Settle the name before you ship the thing
  • Ship the smallest honest version
  • Say plainly what the feature does not do

Where RBAC works and where it starts to break

Consider where rbac works and where it starts to break. Defaults are the product. Most people will never open the settings screen, which means the behaviour you chose for them is the behaviour they will experience forever.

Defaults are the product. Most people will never open the settings screen, which means the behaviour you chose for them is the behaviour they will experience forever.

Why FGA needs a rethink

Why FGA needs a rethink deserves its own treatment. Ship the smallest version that is honest about its limits. A feature that does one thing completely beats one that does five things with an asterisk on each.

Defaults are the product. Most people will never open the settings screen, which means the behaviour you chose for them is the behaviour they will experience forever.

Defaults are the product.

Introducing FGA

Introducing FGA deserves its own treatment. Ship the smallest version that is honest about its limits. A feature that does one thing completely beats one that does five things with an asterisk on each.

Defaults are the product. Most people will never open the settings screen, which means the behaviour you chose for them is the behaviour they will experience forever.

How FGA maps to real SaaS architectures

Consider how fga maps to real saas architectures. Defaults are the product. Most people will never open the settings screen, which means the behaviour you chose for them is the behaviour they will experience forever.

Defaults are the product. Most people will never open the settings screen, which means the behaviour you chose for them is the behaviour they will experience forever.

Handling high-cardinality resources in FGA

Consider handling high-cardinality resources in fga. Naming is design work. If the team argues about what to call something, the disagreement is usually about what it is, and shipping before that is settled means shipping the confusion to customers.

Ship the smallest version that is honest about its limits. A feature that does one thing completely beats one that does five things with an asterisk on each.

Where this leaves us

The pattern repeats across every system we have looked at: the hard part is not the mechanism, it is keeping the mechanism honest as the surrounding assumptions change.

If you are working through the same problem and want to compare notes, the docs cover the mechanics and the console shows the behaviour on your own data.

Everything here, already built

Sign-in, enterprise SSO, directory provisioning, roles and an audit trail behind one API. Start with the quickstart and have a working sign-in this afternoon.

Start selling to enterprise customers

Create an account, point sign-in at Paycux, and get back to the part of the product that is actually yours.