RBAC
ExplainedConcept
Also known as: Role-Based Access Control
Authorisation model that grants access based on roles rather than individual users.
RBAC, explained
Written by EduVerseWhat it is
Role-based access control is a model for authorisation: the question of who is allowed to do what. You don’t hand out permissions to people one by one. Instead you define roles such as admin, editor or viewer, attach permissions to each role, and give every user one or more roles.
Why teams use it
Managing permissions per person gets messy fast: someone changes teams and keeps rights they no longer need, or a new colleague is missing half of them. With roles you change access in one place, and it becomes much easier to check who can delete data or see invoices.
An example from work
A ticket asks you to hide the Delete button for regular users. You add a check on the user’s role in the frontend, and in the review a colleague points out that the API route must also return 403 Forbidden to anyone without the admin role. Hiding a button doesn’t protect anything.
Our own explanation, not a quote from the book.
Where it fits
Access control in applications and systems
Coverage in the book
Explained and compared with alternatives, so you know where and why it’s used.