OutlabsAuth
Getting Started

Choosing a Preset

SimpleRBAC vs EnterpriseRBAC in plain language.

OutlabsAuth ships two presets. They share the same core library; the difference is whether you need an organization tree.

Quick chooser

Do you need departments, teams, offices, client orgs, or similar hierarchy?
│
├─ No  → SimpleRBAC
│        Users have roles for the whole app.
│
└─ Yes → EnterpriseRBAC
         Users get roles *inside* entities (and optionally down a tree).

SimpleRBAC

Flat roles for the whole app. Best for blogs, tools, and SaaS without org nesting.

EnterpriseRBAC

Hierarchy, memberships, and tree permissions. Best for companies, franchises, multi-office products.

SimpleRBACEnterpriseRBAC
Best forBlogs, tools, SaaS without org nestingCompanies, franchises, multi-office products
RolesFlat — assigned to the userScoped — assigned via entity membership
Entities / tree permissionsNoYes
Typical exampleexamples/simple_rbacexamples/enterprise_rbac

SimpleRBAC in one sentence

“Who can do what?” — roles and permissions for the whole application.

main.py
from outlabs_auth import SimpleRBAC

auth = SimpleRBAC(
    database_url=os.environ["DATABASE_URL"],
    secret_key=os.environ["SECRET_KEY"],
)

EnterpriseRBAC in one sentence

“Who can do what, where?” — roles apply in an entity context (and optionally to descendants with _tree permissions).

main.py
from outlabs_auth import EnterpriseRBAC

auth = EnterpriseRBAC(
    database_url=os.environ["DATABASE_URL"],
    secret_key=os.environ["SECRET_KEY"],
    # Optional extras:
    # enable_context_aware_roles=True,
    # enable_abac=True,
    redis_url=os.environ.get("REDIS_URL"),  # recommended in production
)

Can I switch later?

You can move from Simple to Enterprise when you need hierarchy, but treat it as a product migration (new entities, memberships, invite rules), not a one-line flip. Start with the preset that matches the product you are shipping in the next quarter.

Go deeper