How do you implement that cache invalidation, assuming a multiple app server environment? Is it something like a separate redis server?
As a user performs activities, this may involve a scenario requiring escalation or revocation of authorization roles and corresponding permissions. Invalidate cache at this moment. Lazy cache updated authorization info upon next request.
(I authored Yosai)