The problem
A platform serving many client organisations needed two checks on every incoming API request: is the caller who they claim to be, and is this client allowed to access this particular data?
What we built
A gateway-level authorisation layer, built in .NET, that checks the token and the client's entitlements before the request reaches the application. It fails closed, logs every decision and adds only a few milliseconds.
Why it matters
Security is handled once, properly, at the edge, so it doesn't have to be rebuilt in every service by every developer.