TL;DR: Authorization decision latency can be cut by redesigning the rule index twice, moving from policy-shaped storage to bitmap-based filtering and then to a simpler custom bitmap that reduced microbenchmark time to 6.6 microseconds, according to Cerbos. The deeper lesson is that data structure fit and allocation behaviour matter as much as raw algorithm choice when authorization sits in the request path.
Editorial analysis by NHI Mgmt Group, based on content published by Cerbos: “From maps to bitmaps (and from bitmaps to bitmaps)”.
By the numbers:
- The rule table benchmark recorded 207 allocations per operation before the bitmap redesign.
Key questions
Q: How should teams decide whether authorization indexing needs a redesign?
A: Teams should redesign when rule lookup, candidate intersection, or temporary object creation becomes a material part of request-path latency.
Q: Why do authorization systems get slower even when the decision logic stays the same?
A: Because the cost often shifts into the data path around the decision.
Q: What are the signs that an authorization index is failing in practice?
A: Look for rising allocation counts, garbage collector activity, and a large gap between microbenchmark results and sustained throughput.
Practitioner guidance
- Profile the authorization hot path Measure where time is spent in candidate selection, intersection, and evaluation so the team can distinguish policy logic cost from data-structure cost.
- Reduce throwaway allocations in the request path Track per-decision allocation counts and remove intermediate maps or temporary bitmaps that are created and discarded on every lookup.
- Test the index against real policy shape Benchmark using production-like rule cardinality, tenant overlap, and dimension density so the chosen structure reflects actual data, not an assumed worst case.
Bottom line: Authorization performance depends heavily on how rules are indexed, not just on how policies are written.
Explore further
View Full Forum → | NHI Foundation Course → | Our Services → | Read the full analysis →
Authorization performance is often a data-shape problem before it is an algorithm problem. The article shows that the request path slowed when rule data had to be intersected through policy-shaped or overly general indexes. Once the binding data was reorganised around queryable dimensions, the system could short-circuit more work and spend less time on allocator overhead. The practitioner conclusion is that authorization design should start with how candidate rules are represented, not only how they are evaluated.
A question worth separating out:
Q: When should teams prefer a simpler bitmap over a compressed bitmap structure?
A: Prefer a simpler bitmap when the candidate universe is modest, the bitmaps are not sparse in a way that benefits from container compression, and the overhead of a richer structure outweighs its gains. If the data fits in a small, predictable word array, the simpler representation often wins on both speed and memory.
👉 Read our full editorial: Bitmap indexing for authorization decisions: why data shape wins