Evolving Auth: From RBAC to Scopes and Teams — Pavan Kulkarni, WorkOS | Enterprise Ready Conf 2025 @WorkOS
Evolving Auth: From RBAC to Scopes and Teams — Pavan Kulkarni, WorkOS | Enterprise Ready Conf 2025  @WorkOS
Uploaded November 2025 | Updated September 2026, 2 days ago
WorkOS engineering manager Pavan Kulkarni explains how authorization differs from authentication, when startups should care, and why AI compresses the timeline to enterprise. He outlines an evolution from basic RBAC to IDP‑driven automation, resource‑scoped roles (“scopes”), and group‑level permissions—plus pragmatic advice to avoid repeated rewrites.

CHAPTERS:
0:03 - Intro and why authorization is unique
1:04 - Authentication (who you are) vs authorization (what you can do)
1:15 - Authz starts when selling to organizations
1:49 - AI compresses timelines; early enterprise buying
2:13 - Expect to rewrite authz 3× as complexity grows
3:07 - Fragmented ecosystem; need solutions that evolve
3:20 - Today: basic RBAC in WorkOS
3:50 - Automate access via IDPs (SSO, SCIM, groups, attributes)
4:38 - Evolving to resources/workspaces/projects
5:34 - Resource‑aware roles/permissions via scopes
6:00 - User groups/teams; group‑level privileges
7:50 - Advice: don’t DIY authz; start higher and move fast
8:42 - Be ready for Fortune 500 contacts on week one
Evolving Auth: From RBAC to Scopes and Teams — Pavan Kulkarni, WorkOS | Enterprise Ready Conf 2025Agentic Apps: The Next Evolution of User Onboarding — Madison Packer, WorkOS | MCP NightGPU Scheduling for AI Inference: What You Need to Know — Philip Kiely, Baseten | re:Invent 2025Ship AuthKit in 90 Languages with AI Translation — Jason Barry, WorkOS | Enterprise Ready Conf 2025
WorkOS |

Evolving Auth: From RBAC to Scopes and Teams — Pavan Kulkarni, WorkOS | Enterprise Ready Conf 2025

SHARE TO X SHARE TO REDDIT SHARE TO FACEBOOK WALLPAPER