RBAC assigns permissions to roles rather than individual users, centralizing access management. It reduces administrative complexity, improves auditability, and enforces least‑privilege policies. RBAC is widely adopted across enterprise architectures and affects governance and system design. Implementation requires role modeling, governance, and technical in…
Use this profile to understand the building block briefly, place it in the model, and switch to the 360° assessment when needed.
Theoretical construct: explains a term, principle, or mental model.
What organizes, connects, or makes decisions possible.
RBAC is an authorisation model that assigns permissions to roles and connects users to those permissions through role assignments.
RBAC was developed as a formal model for scalable access control and refined through research and standards. NIST’s RBAC overview identifies roles, permissions, and sessions as core model elements.
A role bundles permissions for a task such as approving invoices. A user receives the role under defined conditions, and a session activates the rights relevant to a particular access context. Role hierarchies, separation of duties, and constraints can restrict risky combinations. RBAC simplifies administration and auditing, but cannot correct poor role design or excessive privileges by itself.
Roles bundle authorised operations; users receive those operations indirectly through role assignment.
A session activates a user’s roles for a particular access context.
Hierarchies, separation of duties, and other constraints limit risky combinations of rights.
RBAC supports accountable access management in applications and organisations. It requires maintained role design, clear ownership, and regular review; it does not replace authentication and may be insufficient for dynamic context decisions.
Where this building block is located in the topic model.
No structure path available.
Explore how this building block connects to concepts, methods, technologies, and tools.
These sources establish the term and its professional meaning.
All direct connections of the current building block in a compact text view.
This classification shows where the building block typically matters, how demanding it is, and what kind of impact it has in the model.
The level within the organization (enterprise, domain, team) at which the AssetBlock is applied.