Backend / Security · 2026
argus-trail
argus-trail is a Rails engine that adds role-based access control and permission checks to an existing application with minimal integration work, while recording every permission-relevant action to an append-only audit log.
The problem
Most RBAC libraries either hardcode a fixed role model or require significant schema changes to adopt. Teams adding access control to an existing app needed something that layered on top of their current models without a rewrite, and compliance review needed a reliable record of who changed what permission and when.
The solution
Designed a Rails engine that attaches role and permission concerns to existing models via a small DSL, backed by a normalized roles/permissions schema. Every grant, revoke, and permission check that matters for compliance is written to an audit log table with the actor, target, and timestamp.
Architecture
A Rails engine mounts its own migrations and models alongside the host application. Role and permission lookups are memoized per-request to avoid N+1 authorization checks, and the audit log writes are queued through Active Job so they never block the request path.
Results
- Adopted with less than a day of integration work in internal projects
- Audit log satisfied access-review requirements without a bespoke logging layer
- Zero measurable latency impact on authorization-heavy request paths