At Dubizzle Labs we had three CRM products: Propforce, Jarvis and Carforce. Each held its own data. Each had its own permission model. Anyone who needed an answer that crossed them opened three tools and held three mental models in their head.
The goal was one natural-language client in front of all three. I built it on MCP: a dedicated server per product, each reading straight from that product's RDS, Elasticsearch and existing API layer, with a custom client handling artifacts, multi-turn memory and context across sessions.
The data layer was the easy part. The hard part was a question every unified system eventually has to answer.
Whose rules decide?
When a user asks the client something, who decides what they are allowed to see? There were two real options.
Option A: a central permission layer. Pull every product's roles and grants into one place, check requests there, and let the client trust that answer. The case for it is real. One place to audit. One model to reason about. One check per request.
Option B: per-product RBAC. Every request goes to the product it concerns, and that product's own auth model validates it, exactly as it would for a request from that product's own UI.
I chose B.
Never copy permissions. Route through them.
Why routing won
A central permission layer is a copy. The moment you build it, you own a second source of truth for something three other teams already own. Each product keeps evolving its roles on its own schedule, and every change now has to land in two places. The copy drifts. It always drifts, and when it does the failure is the worst kind: someone sees data they should not, and nothing errors.
Routing has no copy to drift. Each product's auth stays authoritative because it is the only auth. Three products share one client with no permission logic rebuilt anywhere, and access stays correct as each product changes, without anyone remembering to sync anything.
What it cost
Routing is not free. A question that spans products becomes several authorised calls rather than one, and the client has to merge answers that came back under different rules. That is real work in the client.
But it is work in one place I own, written once. A central copy is work in a place everyone depends on, repeated every time any product changes its mind. Given the choice, I will take the cost I can see over the one that arrives later, silently.
The platform shipped end to end in a week. The decision behind it is the part I would make again on any system that sits in front of things it does not own.
