# fga

Source: https://startwithidentity.com/glossary/fga/
Last updated: 2026-08-29
License: content by Start with Identity. Cite the source URL.

---

Authorization at the level of individual resources or fields, rather than at the application or role level. Critical for multi-tenant SaaS, collaborative documents, and sharing patterns. ReBAC is the dominant implementation pattern.

Fine-grained authorization is the problem roles cannot solve: "can this user view this specific document" depends on relationships that change constantly and are owned by the application, not by the directory. Google's Zanzibar paper made relationship-based checks the dominant pattern, and the open implementations that followed made it buildable. The hard parts are consistency (a permission check that reads stale data grants stale access) and latency, since every request needs a decision.

See also: [ReBAC](https://startwithidentity.com/glossary/rebac/), [ABAC](https://startwithidentity.com/glossary/abac/), [RBAC vs ABAC vs ReBAC](https://startwithidentity.com/guides/fundamentals/rbac-vs-abac-vs-rebac/), [authorization vendors](https://startwithidentity.com/vendors/authorization/)
