Devops
RBAC Laravel : Jetstream + Spatie

π Feature 1: Global Roles & Permissions (Most Common)
In this setup, your Jetstream Teams and your Spatie Roles exist in two completely separate worlds.
- How it works: A user has a specific role (e.g.,
Admin,Editor,Premium User) that applies to the entire application, regardless of which team they are currently viewing or managing. - Jetstream’s Role: Jetstream handles the concept of teams, billing workspaces, or shared groups.
- Spatie’s Role: Spatie manages system-wide application access.
- Real-World Example: A SaaS platform where a user is a “Premium Member” (Spatie Global Role) across the whole site, but they can still create and switch between different corporate projects/teams (Jetstream Features).
π₯ Feature 2: Team-Based Roles & Permissions (Advanced RBAC)
In this setup, a userβs roles and permissions are tied directly to a specific team. When they switch teams, their permissions completely change.
-
- How it works: Spatie overrides its global nature and hooks directly into Jetstream’s
Teammodel. - Dynamic Scoping: A user can be an
Owner/Adminin Team A, but just a regularViewerwith restricted permissions in Team B. - Real-World Example: Like GitHub or Slack. You might be an administrator in your own company’s workspace (full access to billing, settings, and code repositories), but a restricted “Guest” or “Collaborator” in an external client’s workspace.
- How it works: Spatie overrides its global nature and hooks directly into Jetstream’s
| Feature / Capability | Global Setup (Separate Worlds) | Team-Based Setup (Integrated) |
|---|---|---|
| Permission Scope | Application-wide. Valid everywhere. | Isolated. Only valid within the active team. |
| Spatie Configuration | No extra config needed (Keep teams_permissions false). |
Requires setting 'teams_permissions' => true in Spatie’s config file. |
| Database Structure | Clean. Spatie links permissions directly to the user_id. |
Complex. Spatie links permissions to a compound key: user_id + team_id. |
| Context Switching | Seamless. No extra code required when users change teams. | Requires running setPermissionsTeamId($teamId) whenever a user switches teams. |



