Permit.io scaled relationship-based access control past 100 million identities on SurrealDB
Permit.io provides permissions for the AI era through full-stack authorisation as a service, so developers can build and enforce fine-grained permissions in any application. Its relationship-based access control now runs on SurrealDB embedded in Rust.
Challenge
Graph queries are central to how Permit.io enforces policy: a check walks from a user through organisations, projects and environments to a resource. The company had built its own in-memory graph engine for Open Policy Agent to run those walks.
In memory, the engine hit a ceiling past tens of millions of relationships. Enterprise customers pushing 10 million to 100 million identities were running into hard technical limits, and memory constraints and complexity were the cause.
Permit.io also serves three kinds of environment: multi-tenant cloud, on-premises in regulated industries, and hybrid. Whatever replaced the in-memory engine had to run in all three without a different architecture for each.
Solution
Permit.io replaced the in-memory engine with SurrealDB's graph-native query engine. Recursive SurrealQL queries traverse users, organisations, projects, environments and resources in milliseconds, at a scale the in-memory approach could not reach.
SurrealDB embeds directly into Permit.io's Rust services, so lightweight policy decision points run at the edge with centralised policy storage behind them. The same engine serves cloud, on-premises and hybrid deployments.
Namespaces and databases isolate thousands of customers' identity graphs from one another while keeping performance and security, on one platform.
Results
The fastest ReBAC solution
Permit.io delivers the fastest and most comprehensive Google Zanzibar-influenced relationship-based access control in the market.
Identities at enterprise scale
Permissions across tens of thousands of folders and millions of files resolve in one query, for customers past 100 million identities.
Three deployment environments
Cloud, on-premises and hybrid run on the same engine with minimal re-architecture.
One centralised policy service
A unified policy enforcement service spans hybrid cloud and the edge.









