RBAC
Role-Based Access Control. Permissions are bundled into roles, users are assigned roles. Simple to understand and audit, but role explosion is a common failure mode at scale. Almost every modern access model starts with RBAC and adds finer-grained controls on top.
RBAC's strength is that a human can read an assignment and understand it, which is why auditors like it and why it will not go away. Role explosion is the standard failure: every exception becomes a new role until there are more roles than users. The workable pattern is a small set of coarse roles for the bulk grant, with attributes or relationships handling the conditions that would otherwise multiply roles.
See also: RBAC vs ABAC vs ReBAC, ABAC, role mining, entitlement
Related on Start with Identity
- GlossaryFine-Grained Authorization (FGA)
Authorization at the level of individual resources or fields, rather than at the application or role level. Critical for multi-tenant SaaS, collaborative docume
- GlossaryReBAC
Relationship-Based Access Control. Authorization is computed by traversing a graph of relationships between subjects and resources. Popularized by Google's Zanz
- GlossaryRow-Level Security (RLS)
Row-level security (RLS) is a database feature that decides which rows a query may read or change based on who is running it, enforced by the database itself ra
- ExpertCo-author of the NIST RBAC model
David Ferraiolo co-authored "Role-Based Access Controls" with Rick Kuhn, presented at the 15th National Computer Security Conference in October 1992. The NIST m
- ExpertCo-author of the NIST RBAC model
Rick Kuhn co-authored the 1992 NIST paper on role-based access control with David Ferraiolo and has worked on the model, its formalization, and its assurance ev
- GuideFrom RBAC to ReBAC: when and how to migrate
RBAC is great until your customers need to share individual resources, not entire roles. The moment you find yourself adding a 50th role named like `editor_for_