SECAI Core · phase 10 of 15 · noun

Role-based access control

An access control model where resources are protected by ACLs that are managed by administrators and that provide user permissions based on job functions.

The Explain card

Plain English
Role-based access control (RBAC) protects resources with ACLs managed by administrators, granting permissions according to job function rather than to individuals one by one.
Example
An AI platform defines roles like "model developer", "model approver" and "auditor". Developers can train and test, approvers can promote to production, auditors can read logs but change nothing. Joining or leaving a team means changing one role assignment, not dozens of permissions.
Why it matters
Roles make permissions reviewable. Defenders can answer "who can push a model to production?" in one query, and separation of duties stops one person training, approving and deploying alone.
Hook
Permissions follow the job title, not the person.

Word knowledge

How the word is built, where it came from, and what it sits beside in memory.

In a sentence

The security team uses role-based access control to let database administrators modify schemas while allowing analysts to run read-only queries.

Why these words
  • role French rôle, a roll or list identifies the phrase's organizing unit
  • based English based, formed from base links role to the system built upon it
  • access Latin accessus, approach or entrance names the action being regulated
  • control Anglo-French contrerolle, a register used for checking names the broader technical practice
Where it came from
Origin
English computing coinage formed from role-based and access control
Entered the language
1990s
What changed
Role moved from a theatrical part to a social or occupational function, while access and control acquired specialized computing senses.
How it is spelled
Pattern
Role-based is hyphenated because role and based jointly modify access control.
Pattern
Access control remains two open words.

Spelled like

  • attribute-based access control
  • rule-based access control
  • role-based authentication
Broken into chunks
  • role-based
    • attribute-based
    • rule-based
    • policy-based
  • access control
    • admission control
    • traffic control
    • version control
What it sits beside

Same subject

Same shape

access control models

role-based security terms

  • role assignment
  • role hierarchy
  • role permission
  • role separation

Where it sits in the deck

Phase 10: Identity, Access, and Cryptographic Foundations

Before examining threats to systems, establish the foundational security primitives — identity, authentication, authorization, and the cryptography underpinning them.