Identity & access layer for a transport platform
Every service sat behind one shared static-RBAC gateway that tangled authentication with authorization. I turned the enterprise identity standard into a buildable transport-domain design and built the replacement: per-app, policy-based access with a dedicated identity provider, policy-as-code, and an API gateway provisioned as code.