{
  "id": 89098,
  "title": "HubSpot Redesigns JITA Authorization with Rule Engine Architecture",
  "url": "https://urgent.news/2026/08/03/hubspot-redesigns-jita-authorization-with-rule-engine-architecture",
  "topic": "tech",
  "section": "Tech",
  "published": "2026-08-03T13:59:00.000Z",
  "source": {
    "name": "InfoQ",
    "slug": "infoq",
    "url": "https://www.infoq.com/news/2026/08/hubspot-jita-rule-engine/"
  },
  "original_language": "en",
  "account": "HubSpot has revamped its Just-In-Time Access (JITA) authorization system using a rule engine architecture, making access decisions more observable and explainable. The system assesses temporary access requests through distinct rules, as opposed to embedded conditional logic, enabling engineers to examine how individual policies influence access decisions and oversee authorization requirements as they evolve. HubSpot's JITA platform handles about 5,500 access requests daily for around 10,000 employees. Previously, the system depended on escalating conditional logic as new access situations emerged. Although this approach maintained existing requirements, engineers struggled to ascertain why a request was granted or denied and which specific checks contributed to processing delays. The revamped architecture incorporates a rule engine where authorization policies are evaluated as standalone rules arranged in a directed acyclic graph (DAG). Each rule yields structured output containing evaluation results, execution timing, and metadata to elucidate the authorization decision. The redesign prioritized decision transparency. The engineering team recognized the necessity of moving beyond confirming whether the authorization system functioned effectively to comprehending the reasoning behind individual decisions. The question was not merely \"does this function?\" but rather \"can we explain every decision this system renders, to anyone, at any point?\" The architecture separates shared request data from individual authorization rules via a shared context object. User attributes, team information, and request details are gathered prior to evaluation and supplied to rules during execution. This strategy diminishes duplicate data retrieval and upholds consistent inputs across authorization checks. The system also incorporates rule-level observability. Rather than merely measuring the overall authorization request, engineers can scrutinize individual rule execution times, failures, and outcomes. This delivers visibility into slow evaluations and the contribution of specific policies to authorization processing. HubSpot employs separate rule execution to manage failures during evaluation. If a rule encounters an error owing to an unavailable dependency or unexpected condition, the failure is documented while other rules proceed with evaluation. Access decisions still rely on the outcomes stipulated by authorization rules. The transition entailed operating the legacy and new authorization systems concurrently and contrasting decisions before transmitting production authorization requests through the new implementation. The team also established regular reviews involving security, product, and operational stakeholders to evaluate whether rules stay adequately restricted and aligned with access prerequisites. The recertification dashboard exhibits usage metrics and execution statistics per rule (Source: HubSpot Blog Post). Similar methodologies have surfaced across the sector, albeit implementations differ based on the type of access being governed. Open Policy Agent (OPA) offers a policy-as-code paradigm that isolates authorization decisions from application logic through a distinct policy engine. Google Cloud's Privileged Access Manager centers on temporary activation of privileged cloud privileges with approval workflows and audit trails. Microsoft Entra Privileged Identity Management similarly oversees just-in-time activation of privileged roles. These systems accentuate declarative policies or identity governance, while HubSpot's approach emphasizes application-specific access workflows with rule-level execution transparency. By introducing a rule engine, structured decision metadata, and governance procedures, HubSpot has transitioned JITA authorization from embedded conditional logic towards a system where access decisions can be evaluated, monitored, and reviewed over time.",
  "summary": "HubSpot has redesigned its Just-In-Time Access (JITA) authorization system using a rule engine architecture. The system evaluates access requests through independent rules organized as a directed acyclic graph, adding structured decision metadata, rule-level observability, and governance workflows to replace complex conditional authorization logic. By Leela Kumili",
  "key_points": [],
  "editors_take": null,
  "illustration": null,
  "coverage": {
    "outlets": 1,
    "also_reported_by": []
  },
  "ai_generated": true,
  "disclaimer": "Summaries, key points and the editor’s take are written by software from other outlets’ reporting and may contain errors — always check the linked original."
}