A cached permission is not forever
Caching "can this user edit invoice 42?" is fine for latency. Caching forever is how yesterday's revoke becomes today's silent allow.
If you cache authorization decisions:
- Key them on actor + action + resource (and tenant)
- Cap TTL tightly
- Invalidate on role, permission, or membership changes
- Prefer re-checking on writes even when the cache says allow
Authn tells you who. Authz decides each action. A warm cache does neither if it is stale.
