Rose Digital · New York Lottery
Cognito SSO, RBAC, Audit Logging, and Security Controls
Legacy auth across a public app left no central identity model, and the admin console had no audit trail.
Situation
The New York Lottery platform served millions of public users through mobile and web apps, with an internal admin console for operators managing games, retailers, and user lifecycles. Authentication had grown service-by-service: inconsistent token validation, no shared SSO, and admin actions with no durable audit trail.
Risk or constraint
Security reviews flagged auth as a systemic weakness. Bulk user operations in the admin console had no RBAC model, any authenticated admin could perform any action. Compliance and incident response both required an audit log that didn't exist.
Diagnosis
Auth wasn't a feature gap, it was an architecture gap. Without a central identity provider, every Lambda reimplemented verification differently. Without RBAC and audit logging at the API layer, the admin console was a liability waiting for a compliance questionnaire.
Work completed
- Built multi-tenant Cognito SSO with custom Lambda authorizers and JWT verification across API Gateway routes
- Replaced legacy auth flows without breaking existing user sessions during migration
- Delivered an Admin Console API with role-based access control and bulk user lifecycle operations
- Persisted audit logging on Aurora Serverless, who did what, when, and to which resource
- Applied least-privilege IAM per admin function so RBAC extended from API to AWS execution role
Measurable result
- Cognito SSO
- Multi-tenant identity replaced legacy auth
- RBAC
- Role-gated admin operations
- Audit log
- Durable trail on Aurora Serverless
Architecture or technologies
- Amazon Cognito
- Lambda authorizers
- API Gateway
- Aurora Serverless
- Node.js
- JWT
- IAM
What I would improve next
- Fine-grained ABAC policies for admin roles that map to organizational structure
- Real-time alerting on anomalous admin actions (bulk deletes, privilege escalation)
- Automated access reviews and session revocation for dormant admin accounts
Request a readiness assessment
If this pattern matches what you're seeing, describe your situation, not a job spec. I'll reply within 48 hours with an honest read.