---
title: "Nook"
description: "Customer success story: How Cerbos helped Nook build secure and extensible roles and permissions"
customer: "Nook"
website: "https://nook.io"
canonical: "https://www.cerbos.dev/customers/nook"
image: "/assets/use-case-files/social/nook-case-study-url-thumbnail.png"
source: "https://www.cerbos.dev/customers/nook"
---

# Nook onboards 3x more users by implementing granular roles and permissions

Using Cerbos for their authorization layer, Nook allows businesses to bring more stakeholders into the accounts payable workflow, streamlining essential financial processes for their users.

## At a glance

- Increased number of user roles available in the product
- Secure and reliable access gating for sensitive resources
- Increased customer adoption with better user experience

> For every client we have, we're able to have 2x, 3x, the number of users for that client on Nook than we could without the roles and permissions that we have.
>
> — Henry Arnold, CTO & Co-Founder, Nook

### Summary
<a href="https://nook.io/" target="_blank" rel="noopener noreferrer">Nook</a> delivers simplified payments and invoicing solutions and provides integrated accounts payable and accounts receivable for modern finance teams. Nook’s all-in-one platform enables organizations to streamline their accounts payable workflows. Cerbos is an open-source authorization layer enabling secure and extensible roles and permissions. Nook used Cerbos to build a sophisticated access control system that allows finance teams to bring a wide range of stakeholders into their workflows without exposing sensitive information.

[Watch the video](https://www.youtube.com/watch?v=dISpXMv5r8s)

## Introduction

### Filling a market need in business finance tools

Henry Arnold, and Joe Lines, CTO, and CEO respectively, co-founded Nook to solve a common problem found in business finance applications. Most only allow users specifically on the finance team. This limitation has security benefits, as financial data is sensitive and requires strict protection protocols. But in reality, the finance team interacts with a wide range of internal and external stakeholders. 

“We're helping businesses pay their suppliers,” Henry Arnold explains, “and what we realized early is that there are lots of different roles that should exist inside that process, but today, most accounting software is focused on the finance team and they can see everything.” 

Henry and Joe wanted to create an application that could include those stakeholders in a finance team’s workflow so their processes weren’t fragmented between different systems and modes of communication.

> There are lots of different roles that should exist, but today, most accounting software is focused on the finance team and they can see everything.
>
> — Henry Arnold, CTO & Co-Founder, Nook

## Business Needs

### Safely bring all stakeholders into the same system

You may not spend time thinking about how many different people touch financial information within a business. But Joe and Henry do. They mapped out in detail each of the roles they wanted to include in their application and thought carefully about what type of access controls were needed for each role. 

According to Henry, “The business owner ultimately controls the funds. The finance team executes payments. You have a finance team or an accountant, internal or external. There's maybe a payroll team. And then there's operations teams who only need to have visibility of the invoices that they're involved in.” 

He continues, **“At the heart of the original vision for Nook was to create an accounts payable product that allowed us to bring in those other functions that exist** within the acquisition of products and make sure that they're able to make the right decisions, **but also limit what visibility they have of sensitive financial information.”** 

## Why choose a decoupled solution?
**To take advantage of a battle-tested solution**   Joe and Henry considered a centralized authorization layer a critical component of their application. So they opted for a decoupled solution from the beginning. They had already been following Cerbos for months, and were confident in it’s ability to meet their requirements.   'Almost everything we've decided to do, we've done it properly. We didn't try and do a half-baked approach,' says Henry, 'There's been some degree of thought that's gone into what roles and permission should look like, which is gonna be tens of thousands of hours, more thought than we were ever gonna be able to put into it. So, as founders, **We want to work with partners who have thought this through in much greater detail than we have the capacity to do.**'  The two founders trusted Cerbos’s authorization solution because they knew it had been built by people with special expertise, and battle tested by numerous other companies.   **To position the product for future growth**  Nook was still near the beginning of it’s life when Joe and Henry implemented Cerbos, so they were in a prime position to set a foundation for future scalability. They knew that a decoupled solution would be easier to update when requirements changed in the future. Cerbos was founded to help developers avoid spending months re-configuring their authorization policies every time the business requirements changed.  **Henry and Joe also want to empower product owners and business owners to manage access controls, rather than tying roles and permissions to the engineering team.** Product owners’ visibility into customer issues makes them able to define different roles for customers with a clear understanding of their needs and use cases. Creating that strong connection to the end customer will make a huge difference in Nook’s ability to scale the product.

## Results

### Extensive permissions allow Nook to serve 3x more users per client

By partnering with Cerbos, Nook is able to apply granular access controls to a range of financial functions, including payroll, bank transactions, and invoicing. Their customers can now bring different user groups into the product, and customize access to each function for each user. 

Henry shares an example, **“Businesses can onboard accountants and either let the accountants maintain the books for them, but not execute payments, or they can actually empower the accountants to execute payments against invoices”**

Nook users can also include additional external stakeholders who are relevant to their processes. For example, a warehouse manager can be granted access to approve or reject specific invoices pertaining to items that move through that warehouse. “You can have a business owner, a couple of people on the finance team, and then eight or so people in there solely for approving things,” Henry adds.

The best part is that delivering this value to their customers directly translates to Nook’s business growth. **Henry and Joe estimate that Nook can onboard 3 times the number of users per client than the market standard**, with the top use case at the moment being 12 users. 

“For every client we have, we're able to have 2x, 3x, the number of users for that client on Nook than we could without the roles and permissions that we have.” Joe says,  “The product relies on Cerbos to bring the detailed roles that we want.” 

The team at Nook confidently navigates the complexities of accounting system permissions, assured that their authorization logic is sound and secure. The granular permissions structure Nook built delivers unmatched value to their customers. And Nook’s developers can move fast, building features and scaling the business without getting bogged down in arduous authorization management processes. 

> It allowed us to bring on different user groups into the products and be part of that accounts payable flow. When we started out, that's one of the things we thought was really missing from the other products in this space.
>
> — Henry Arnold, CTO & Co-Founder, Nook

#### Related links

- <a href="https://www.cerbos.dev/blog/how-cerbos-helped-nook-build-secure-extensible-roles-permissions">Full interview with Joe Lines and Henry Arnold</a>
- <a href="https://www.cerbos.dev/customers/debite">Debite accelerates compliance certification and ships products faster</a>
- <a href="https://www.cerbos.dev/customers/9fin">9fin modifies product packaging in 10 minutes</a>

#### Learn more about Cerbos

- <a href="https://www.cerbos.dev/features-benefits-and-use-cases/product-packaging">Product packaging with Cerbos</a>
- <a href="https://www.cerbos.dev/features-benefits-and-use-cases/abac">ABAC (Attribute-based access control)</a>
- <a href="https://www.cerbos.dev/features-benefits-and-use-cases/rbac">RBAC (Role-based access control)</a>
- <a href="https://www.cerbos.dev/features-benefits-and-use-cases/permission-aware-data-filtering">Permissions-aware data filtering</a>
