February 26, 2026 · Foundation · Authorization + Billing

Authorization + billing substrate — OpenFGA and Lago land as first-class

Two invisible-but-load-bearing substrate pieces: OpenFGA answers per-resource authorization questions (not role checks), and Lago handles metered consumption between the platform and Stripe. Every tier-gated feature and metered service downstream of this week inherits both.

What changed

Two platform-layer pieces landed this week that don’t look like a product update but change what the platform can do: OpenFGA for authorization and Lago for billing and metering. Every plan-tier gate, every per-resource permission check, and every consumption meter downstream of this change now goes through them.

Authorization
OpenFGA, a Zanzibar-style open-source authorization service originally built at Auth0, is now the reasoning engine behind every read and every write. Decisions ground in user → role → resource → scope rather than a hard-coded conditional.
Billing & metering
Lago, an open-source metering and billing platform, now sits between the platform and Stripe. Every plan entitlement is expressed as a Lago rule, and every event that touches a meter flows through Lago before it becomes a Stripe invoice line.
Resource scope
A compliance manager on an Ultra plan can see and manage all of their organization's controls but not the DD room a partner org is running an engagement inside. A partner analyst granted a specific engagement sees only that engagement's artifacts. An auditor invited into a tenant reads only the evidence they were scoped to.
Consumption limits
AI-grounded tool usage can be metered in real time, capped per organization to prevent runaway spend, and rolled into a Stripe invoice automatically. No custom billing plumbing per surface.

Why it matters

The auth layer used to answer “does this user have this role?” It now answers “does this user have this permission on this specific resource?” The scoping is a first-class property of every call, not an afterthought in each service.

Neither piece is customer-visible on its own. Together they are what makes every subsequent tier-gated feature, per-resource permission, and metered service actually work at the platform layer instead of being an afterthought in each service. Every product update downstream of this week inherits both, and there are a lot of them.

Availability

Live on every plan tier. Both services are already in the hot path for every read, write, and metered event the platform performs.

The switchover happened in place. Existing roles and entitlements continue to resolve the same way for current users, and existing Stripe subscriptions keep their current billing cadence; the Lago layer sits in front of invoice generation rather than replacing the subscription itself.

Known limitations

This is the first iteration of the authorization model and the metering catalog. Each new product surface adds its own OpenFGA types and Lago meters as it lands, so coverage grows per release rather than arriving as a single catalog.

Permission decisions and meter events are evaluated per call, not cached across requests. High-volume read paths pay a small latency cost on every check in exchange for the scoping being accurate the moment a grant is revoked.