---
title: "Supy"
description: "Customer success story: Supy offers dynamic role management to their clients with Cerbos"
customer: "Supy"
website: "https://supy.io/"
canonical: "https://www.cerbos.dev/customers/supy"
image: "/assets/use-case-files/social/supy-case-study-url-thumbnail.png"
source: "https://www.cerbos.dev/customers/supy"
---

# Supy offers dynamic role management to their clients with Cerbos

A back-of-house restaurant management software improves customer satisfaction and growth by offering clients the ability to create custom roles and permissions for their accounts.

## At a glance

- Increased customer satisfaction
- Enhanced operational efficiency
- Improved security and compliance

> Offering dynamic roles and permissions makes us more competitive in the market. We’re providing companies with a software that can be adapted to their workflows.
>
> — Ibrahim Bou Ncoula, CTO, Supy

### Summary
<a href="https://supy.io/" target="_blank" rel="noopener noreferrer">Supy</a> is a restaurant management software. 30% of their clients were asking for custom roles and permissions, so Supy needed an efficient, scalable way to manage diverse and dynamic authorization policies both in their back-end and their customer UI. Cerbos is a solution that externalizes authorization and offers a central policy management hub to monitor and orchestrate access control in multi-tenant systems. Supy integrated Cerbos with their software and increased customer satisfaction, reduced demands on engineers’ time, and improved security and compliance.

## Introduction

Supy, the leading restaurant management software for multi-branch restaurants, encountered scalability and security issues with its internally developed role-based access control (RBAC) system. Originally managing static permissions via MongoDB, Supy realized the system's limitations in scalability, maintenance, and security.

“At the time we only had a few roles, each with their own set of permissions, which we mapped manually to the database. And we were adding a couple of roles every month as clients requested them,” said Roman Levytskyi, lead engineer at Supy. He could clearly see that as their client base grew, creating ad hoc roles and permissions was going to become an untenable workload, and likely a security vulnerability as well.

## Business Needs

### Meeting customer demand for flexible permissions

Supy’s software manages critical restaurant operations such as procurement, inventory management, kitchen operations, integrations with accounting & POS systems, and more. Many restaurants distribute business responsibilities differently among staff, necessitating customizable roles and permissions.

Approximately 30% of Supy's customers sought tailored roles, highlighting the need for a solution that offered dynamic role creation without extensive engineering support. To cater to diverse restaurant operations, Supy required a flexible and responsive role-based access control (RBAC) solution.

“Each company has their own rules for how they manage their restaurants, and we knew that not having custom roles was going to be a deal breaker for some of our target clients,” said Ibrahim Bou Ncoula, Supy’s CTO.

#### Requirements

- **Dynamic Role Management:** Enable customers to define and manage roles and permissions in real-time through an intuitive user interface.
- **Conditional Access Rules:** Implement custom rules that allow managers to set conditions for specific actions, such as requiring approval for orders exceeding a certain amount (e.g., $1000).
- **Approval Ladders:** Facilitate hierarchical approval processes where designated roles can authorize actions based on predefined rules.

> Each company has their own rules for how they manage their restaurants, and we knew that not having custom roles was going to be a deal breaker.
>
> — Ibrahim Bou Ncoula, CTO, Supy

## Evaluation
Before fully committing to Cerbos, Supy also evaluated other authorization solutions and compared their performance along the following criteria:  **Simplicity and Ease of Use:** Cerbos offers a simpler setup and configuration process compared to other tools, making it accessible to teams without deep policy engine expertise. **Out-of-the-box Functionality:** Cerbos provides essential functionalities like dynamic role management and real-time policy evaluation without needing extensive customization or additional plugins. **Documentation and Support:** Cerbos is supported by comprehensive documentation and responsive support, facilitating smoother implementation and troubleshooting processes. **Community support:** Cerbos community & response from Cerbos core people has been a great motivation to use the tool. **Performance Considerations:** Other tool’s performance can degrade with complex nested models and intricate policy logic, potentially leading to increased latency and resource consumption in high-throughput environments. “Comparing Cerbos with the alternatives was like comparing the iPhone to Android phones. Everything in Cerbos is elegantly thought out and placed intuitively so I don’t have to think about it too much,” said Roman.

> Comparing Cerbos with the alternatives was like comparing the iPhone to Android phones. Everything in Cerbos is elegantly thought out and placed intuitively.
>
> — Roman Levytskyi, Lead Engineer, Supy

## Implementation and Results

Supy implemented Cerbos using its JavaScript SDK, Admin API, and integrated a Postgres adapter for seamless data management. The implementation process included a thorough documentation review to ensure compatibility and ease of integration.

Load testing involved simulating dynamic roles, achieving up to 1,000 random authorization checks per second with 200,000 policies assigned to 50,000 roles in the database. The average response time was 5 milliseconds while continuing to add, disable, and update policies in real time, validating Cerbos' scalability, resilience, and performance capabilities.

#### Technical Results

- **Scalability:** Cerbos demonstrated robust scalability, handling high volumes of policy checks efficiently, which is critical for Supy's growing customer base and increasing transaction volumes.
- **Real-Time Performance:** With an average response time of 5 milliseconds during load tests, Cerbos ensured fast and real-time policy evaluation, meeting Supy's requirement for low-latency access control decisions.
- **Integration Ease:** The JavaScript SDK and Admin API simplified the integration process, enabling Supy to deploy and manage custom dynamic roles and permissions by building a small proxy/management layer on top of Cerbos.

### Business Results

The introduction of dynamic role management with Cerbos helped improve Supy’s customer satisfaction, operational efficiency, and application security.

**Customer Satisfaction and Growth:** The implementation of Cerbos & integration with Supy’s backend not only met, but exceeded customer expectations for flexible and secure access management, fostering deeper customer engagement and attracting new clients seeking robust, customizable solutions.

“Offering dynamic roles and permissions makes us more competitive in the market,” said Ibrahim, “We’re able to offer companies a software that fits into their own workflows, rather than forcing them to change.”

**Enhanced Operational Efficiency:** Cerbos empowered Supy's customers to configure and modify roles instantly, reducing dependency on engineering resources and accelerating time-to-deployment for new access policies.

**Improved Security and Compliance:** Conditional access rules enabled stringent control over sensitive operations, such as financial transactions, while approval ladders ensured compliance with internal policies and regulatory requirements.

#### Related links

- <a href="https://www.cerbos.dev/customers/nook">Nook onboards 3x more users by implementing granular roles and permissions</a>
- <a href="https://www.cerbos.dev/customers/4g-capital">4G Capital saves a quarter-million dollars per year with Cerbos</a>

#### Learn more about Cerbos

- <a href="https://www.cerbos.dev/features-benefits-and-use-cases/ecosystem">Ecosystem</a>
- <a href="https://www.cerbos.dev/features-benefits-and-use-cases/rbac">Role-based access control (RBAC)</a>
- <a href="https://www.cerbos.dev/features-benefits-and-use-cases/scalability">Scalability</a>
- <a href="https://www.cerbos.dev/features-benefits-and-use-cases/flexible-deployment-models">Flexible deployment with low-latency</a>
