# rebac

Source: https://startwithidentity.com/glossary/rebac/
Last updated: 2026-08-29
License: content by Start with Identity. Cite the source URL.

---

Relationship-Based Access Control. Authorization is computed by traversing a graph of relationships between subjects and resources. Popularized by Google's Zanzibar paper. Modern implementations include Authzed SpiceDB, OpenFGA, and Permify.

ReBAC fits the sharing and collaboration model most products actually have: access follows from being an owner, a member, or a parent of something, and those relationships change constantly. Zanzibar-style systems make the check fast and the graph traversable, at the cost of running a new stateful service on the request path and reasoning carefully about consistency when a permission was just revoked.

See also: [fine-grained authorization](https://startwithidentity.com/glossary/fga/), [RBAC vs ABAC vs ReBAC](https://startwithidentity.com/guides/fundamentals/rbac-vs-abac-vs-rebac/), [ABAC](https://startwithidentity.com/glossary/abac/), [authorization vendors](https://startwithidentity.com/vendors/authorization/)
