Skip to content
EduVerse

RBAC

Explained

Concept

Also known as: Role-Based Access Control

Authorisation model that grants access based on roles rather than individual users.

RBAC, explained

Written by EduVerse

What it is

Role-based access control is a model for authorisation: the question of who is allowed to do what. You don’t hand out permissions to people one by one. Instead you define roles such as admin, editor or viewer, attach permissions to each role, and give every user one or more roles.

Why teams use it

Managing permissions per person gets messy fast: someone changes teams and keeps rights they no longer need, or a new colleague is missing half of them. With roles you change access in one place, and it becomes much easier to check who can delete data or see invoices.

An example from work

A ticket asks you to hide the Delete button for regular users. You add a check on the user’s role in the frontend, and in the review a colleague points out that the API route must also return 403 Forbidden to anyone without the admin role. Hiding a button doesn’t protect anything.

Our own explanation, not a quote from the book.

Where it fits

Access control in applications and systems

Coverage in the book

Explained

Explained and compared with alternatives, so you know where and why it’s used.

Appears in