Auth and identity · Pattern

Roles and permissions (RBAC)

A way to manage who can do what by giving each user one or more roles, such as admin, editor or viewer, and giving each role a fixed set of permissions.

Basics · updated

How it works

Instead of granting abilities person by person, RBAC groups them: the 'editor' role may create and edit posts, the 'viewer' role may only read, and each user gets the roles that fit their job. Changing what editors can do then means changing one role rather than hundreds of accounts. Roles are often scoped to a team or workspace, so the same person can be an admin in one organisation and a viewer in another.

Enforcement belongs on the server. A backend checks the role before acting, reading it from a table or from custom claims in the user's token, and a database can enforce it directly: PostgreSQL row level security policies can compare the user's id and role with each row. Hiding a button in the app is only cosmetic. When rules depend on relationships or attributes (the owner of this document, members of this project), finer models take over: attribute-based (ABAC) and relationship-based (ReBAC) access control, with tools such as OpenFGA.

More in Auth and identity

Basics

All 17 Auth and identity terms

Crafted in the dark. Shipped to the world.

Tell us what you are building. You get a private project space with a proposal and a line-by-line quote within a day.