Rolling your own is about the same level of effort, easier to mock/modify/customize as needed.
And if I wasn't rolling my own, I'd look to a library (many in NPM) or I'd look to a Kubernetes sidecar where that makes sense (Dapr or a service mesh).
Going with an API adds concerns about compliance, GDPR, inheriting your entire attack surface, inheriting your downtime risk, configuration foot-guns, and cost.
But I don't like leaving negativity - so here's some suggestions which might tip the value:
- Having really high quality RBAC front-end UI that I can just let you deal with it
- Same for inviting people to join accounts
- Testing utilities, so it becomes really easy to run the same tests with different permissions
- Similar to the above but a browser extension where a superuser can switch to emulate any other user (or admins can switch to any user in their org if policy allows)
- Audit logging and customer facing UI for viewing audit logs