How We Structure Permissions Before the First Customer
A working note on permissions model design — what matters, what does not, and where these projects usually go sideways.
Teams rarely lose money on permissions model design because of the wrong tool. They lose it because the decision was never written down. This post walks the order we actually use.
The problem underneath
The pattern is familiar. Someone raises it in a standup, a decision gets made in ten minutes, and nobody records why.
Six weeks later three people hold three different mental models. The rework costs more than the original choice ever did.
What this looks like in real projects
In projects like these, one version is local. A single workflow strains, everything else is fine, and two focused weeks clear it.
The other reads identically in a status update, but the strain is systemic. Treat that as local and you spend a quarter arriving back where you started.
Mistakes companies make
- Choosing tools before the workflow is written down.
- Scoping version one to cover every edge case.
- Leaving the work unowned, then blaming the tool.
- Skipping measurement, so nobody can prove it helped.
- Treating launch day as the end of the cost.
The first and the last are the expensive ones.
The engineering view on permissions model design
From inside the codebase, permissions model design reduces to three questions. What happens when a step fails halfway. Who finds out. How you reverse it.
Design for partial failure before you need it. Step three fails after one and two succeeded, and that is the case people skip.
Give retries a ceiling and some jitter. A retry storm is an outage you built yourself.
How we approach it step by step
- Reproduce the pain with a real case, not a description of it.
- Write the target outcome as a single number.
- Pick the smallest change that could plausibly move that number.
- Build it with a rollback path.
- Release to one team or a slice of traffic.
- Review in two weeks, then widen, revise, or delete.
Deleting is a legitimate result. It happens less often than it should.
Practical guardrails
- Instrument before optimising.
- Cap spend and volume in code, not on the invoice.
- Write down the decision, not only the outcome.
- Keep one named owner with protected hours.
- Set a review date ninety days out and keep it.
Trade-offs worth saying out loud
Speed against flexibility. Managed service against control. Cheap now against cheap later. None of it is free.
This trade-off usually appears when the second customer wants something the first one didn't. That is the moment to revisit permissions model design, not before.
Common misconceptions
“We need the best available option.” You need the one your team can operate at 2am. Rarely the same thing.
“We’ll do it properly later.” Sometimes true. Put a date on later or it never arrives.
“It’s a one-off.” Anything a customer touches becomes a product, support included.
Frequently asked questions
Can we start without changing the whole system?
Almost always. Pick one workflow, ship it end to end, and keep the old path available until the new one earns trust.
How do we know whether it worked?
Choose the number before you build — hours saved, error rate, response time, or conversion — then compare a two-week window either side.
Is it cheaper to buy a tool instead?
Often yes for the first version. Build when the workflow is a genuine differentiator or no tool fits the data you already hold.
Do we need to hire someone for this?
Not at the start. One named owner with a few protected hours a week, plus a small build team, is enough to prove value.
How long does permissions model design take to get right?
A narrow first version is usually four to six weeks. Anything quoted at three months with nothing shippable in between is a risk, not a plan.
Conclusion
The useful move on permissions model design is almost always the smaller one. Ship a narrow slice a real user can touch this month, measure it, then decide what earns the next four weeks.
Everything gets easier once something is live.
Related reading and next steps
- AI automations — how we run this kind of work.
- product design and UX — how we run this kind of work.
- More writing from the team.
Want a second opinion on permissions model design for your setup? Book a 30-minute call. If it is not worth building, we will say so.
FAQ
Frequently asked questions
Can we start without changing the whole system?+
Almost always. Pick one workflow, ship it end to end, and keep the old path available until the new one earns trust.
How do we know whether it worked?+
Choose the number before you build — hours saved, error rate, response time, or conversion — then compare a two-week window either side.
Is it cheaper to buy a tool instead?+
Often yes for the first version. Build when the workflow is a genuine differentiator or no tool fits the data you already hold.
Do we need to hire someone for this?+
Not at the start. One named owner with a few protected hours a week, plus a small build team, is enough to prove value.
How long does permissions model design take to get right?+
A narrow first version is usually four to six weeks. Anything quoted at three months with nothing shippable in between is a risk, not a plan.
Building something similar?
Let's talk in 30 minutes.

