HubSpot

HubSpot Rebuilds Access Control with a Rule Engine for Smarter Governance

HubSpot's redesign of its JITA authorization system is a smart move toward clarity.

3 min readInfoQ
HubSpot Rebuilds Access Control with a Rule Engine for Smarter Governance

HubSpot's decision to rebuild its Just-In-Time Access authorization system around a rule engine architecture is a rare instance of engineering maturity meeting operational reality. For years, JITA has been the quiet workhorse of secure access, but its conditional logic often grew into a tangle of nested if-statements that were brittle, opaque, and nearly impossible to audit. By reorganizing access decisions into independent rules mapped as a directed acyclic graph, HubSpot is not just cleaning up code; it's acknowledging that authorization is no longer a one-time setup but a living system that needs structure, visibility, and the ability to change without fear. This feels like a natural evolution for teams that have outgrown simple role-based access control, and it's a signal that the industry is finally ready to treat permissions as a first-class engineering problem.

What stands out here is the emphasis on rule-level observability and structured decision metadata. That might sound like internal plumbing, but for anyone who has ever tried to answer the question, "Why did this user get access?" it's the difference between a black box and a transparent contract. The old approach often forced teams to trace through a single, monolithic check. Now, with independent rules and a clear graph, you can point at a specific node and say, "This rule fired, this one didn't, and here's the metadata to prove it." This is the kind of architectural shift that doesn't just improve security; it makes governance workflows practical rather than performative. For organizations wrestling with compliance audits or internal reviews, that's not a nice-to-have. It's the difference between a three-week investigation and a thirty-minute explanation.

This move also dovetails with broader trends we're seeing across the infrastructure space. For instance, the exploration of AI deployment topics at QCon AI New York includes agent authorization as a key theme, which suggests that access control is becoming more dynamic and context-aware across the board. Similarly, the recent Kubernetes 1.37 release with its stable metrics API highlights how much of modern infrastructure is moving toward observable, modular systems. HubSpot's rule engine fits squarely into that pattern: it's less about a single dramatic feature and more about building foundations that can adapt to increasingly complex environments. The parallel is clear; whether you're managing container orchestration or permissions, the era of static, hard-coded logic is ending.

If we were advising a team looking at this, our take would be direct: don't wait for the pain to force your hand. Start small, but start now. Identify the access paths that are hardest to explain or change, and consider how a rule-based approach could give you both flexibility and control. The specific architecture you choose matters less than the principles: independent rules, explicit decision points, and observable outcomes. HubSpot's redesign is a solid reference point, not because it's perfect, but because it demonstrates what's possible when you stop treating authorization as an afterthought and start building it as a structured, governable subsystem. The open question that remains is how this scales under extreme load or in highly heterogeneous environments, but that's a problem most of us would welcome having. The practical takeaway? If your access logs are a source of fear rather than insight, it's time to explore a rule engine of your own.

From InfoQ

HubSpot has redesigned its Just-In-Time Access (JITA) authorization system using a rule engine architecture. The system evaluates access requests through independent rules organized as a directed acyclic graph, adding structured decision metadata, rule-level observability, and governance workflows to replace complex conditional authorization logic.

Read the original at InfoQ