I shipped a complete Roles & Permissions management feature for the ZOOT Admin CMS – live in production, polished, and battle-ready – in under four hours. In a pre-AI world, the same scope (database schema changes, backend APIs, frontend UI with granular role selection and effective permissions computation, plus security validation) would comfortably take one to two weeks. Today, thanks to agentic AI workflows, it took the time of a good pair-programming session.

Why We Needed This Now

ZOOT (getzoot.us) is scaling fast. What started as a fun, free-to-play social gaming platform with arcade originals, quests, loot drps, ribbons, daily rewards, and redeemable Sweeps Coins has grown into a real business with meaningful user value (instant redemptions, VIP tiers, B2B integrations). That growth brings risk: more admins touching sensitive areas like redemptions, store inventory, user data, coupons, and financial reports.

Until recently, our admin access was coarse – mostly “admin” or “not admin.” As the team expanded and responsibilities specialized (Product, QA, CS, Content, DEV, CRM, etc.), we needed least-privilege access controls that match our increasing risk profile. Enter: a proper RBAC (Role-Based Access Control) system with:

  • Predefined functional roles (BASIC, PRODUCT, CRM, CONTENT, DEV, QA, CS, VIP, etc.)
  • Optional extra granular permissions (USERS, REDEEMS, COUPONS, STORE, QUESTS, ZOOT LOOT, B2B GAMES, etc.)
  • Computed “Effective Permissions” view so admins see exactly what they can do
  • A restricted “ROLE AND PERMISSIONS MANAGEMENT” permission itself, locked to a small group for now

The goal? Align access with business needs while minimizing blast radius if credentials are compromised or scopes drift.

How AI Made It Happen in <4 Hours

I opened both the client (React-based admin dashboard) and backend projects in my IDE. Then I leaned on an AI coding agent to do the heavy lifting:

  1. Schema & Backend First – Described the desired data model (roles table, permissions table, many-to-many mappings, plus computed effective perms). The agent generated migrations, models, controllers, endpoints, and the aggregation logic in one coherent pass.
  2. Frontend in Parallel – The agent built the React components: role checkboxes, extra permissions toggles, user ID load button, and live “Effective Permissions” preview. It matched our existing dark theme and responsive layout.
  3. Security & Polish – I audited for over-granting, missing checks, or edge cases. Tweaks focused on ZOOT-specific rules (e.g., elevation requirements). Added validations, errors, and confirmations.
  4. Deploy & Validate – Local tests, staging, prod deploy. Loaded my user, assigned roles, and verified effective permissions locked down correctly.

Total: under four hours, including audits and that celebratory Slack message.

Key Takeaways for this End of November, 2026

  • AI as Full-Stack Pair Programmer – The agent implemented cross-layer features from high-level specs. This is the shift from tools to agent teams – AI amplifies judgment on architecture, risk, and product fit.
  • Speed Enables Better Security – Fast cycles meant more “what-if” testing (e.g., self-revocation checks). In longer timelines, polish often gets cut.
  • Business Risk → Engineering Opportunity – Foundational features like RBAC aren’t flashy, but they enable safe scaling. Tight controls build trust as teams grow.

#builtByAi