SECAI Core · phase 10 of 15 · noun
Role-based access control
An access control model where resources are protected by ACLs that are managed by administrators and that provide user permissions based on job functions.
The Explain card
- Plain English
- Role-based access control (RBAC) protects resources with ACLs managed by administrators, granting permissions according to job function rather than to individuals one by one.
- Example
- An AI platform defines roles like "model developer", "model approver" and "auditor". Developers can train and test, approvers can promote to production, auditors can read logs but change nothing. Joining or leaving a team means changing one role assignment, not dozens of permissions.
- Why it matters
- Roles make permissions reviewable. Defenders can answer "who can push a model to production?" in one query, and separation of duties stops one person training, approving and deploying alone.
- Hook
- Permissions follow the job title, not the person.
Word knowledge
How the word is built, where it came from, and what it sits beside in memory.
In a sentence
The security team uses role-based access control to let database administrators modify schemas while allowing analysts to run read-only queries.
Why these words
- role French rôle, a roll or list identifies the phrase's organizing unit
- based English based, formed from base links role to the system built upon it
- access Latin accessus, approach or entrance names the action being regulated
- control Anglo-French contrerolle, a register used for checking names the broader technical practice
Where it came from
- Origin
- English computing coinage formed from role-based and access control
- Entered the language
- 1990s
- What changed
- Role moved from a theatrical part to a social or occupational function, while access and control acquired specialized computing senses.
How it is spelled
- Pattern
- Role-based is hyphenated because role and based jointly modify access control.
- Pattern
- Access control remains two open words.
Spelled like
- attribute-based access control
- rule-based access control
- role-based authentication
Broken into chunks
-
role-based
- attribute-based
- rule-based
- policy-based
-
access control
- admission control
- traffic control
- version control
What it sits beside
Same subject
- access control list
- least privilege
- authorization
- identity and access management
Same shape
- attribute-based access control
- rule-based access control
- policy-based access control
access control models
- role-based access control
- attribute-based access control
- mandatory access control
- discretionary access control
role-based security terms
- role assignment
- role hierarchy
- role permission
- role separation
Where it sits in the deck
Phase 10: Identity, Access, and Cryptographic Foundations
Before examining threats to systems, establish the foundational security primitives — identity, authentication, authorization, and the cryptography underpinning them.