Role-based access control (RBAC)

Role-based access control grants permissions to roles rather than to individuals, and gives each user only the roles their job requires.

Role-based access control (RBAC) is an access model in which permissions attach to roles and people receive roles, instead of each person being granted permissions one by one. NIST summarizes it in one sentence: "each user is assigned one or more roles, and each role is assigned one or more privileges" (NIST, Role Based Access Control). David Ferraiolo and Richard Kuhn formally introduced the model at the 15th National Computer Security Conference in 1992, and it was standardized as ANSI/INCITS 359-2004, revised in 2012.

The appeal is administrative and evidentiary. When an analyst joins, moves or leaves, an administrator changes one role assignment instead of dozens of individual permissions, and a reviewer can read the access model as a short list of roles instead of a sprawl of exceptions. Two principles do most of the work. Least privilege means each role carries only the permissions its job needs. Separation of duties means conflicting powers sit in different roles, so the person who administers access is not the person whose actions an audit reviewer checks, and the person who approves a control is not its only evidence owner.

In compliance software, RBAC decides who can read restricted material, who can accept or dismiss an alert, who can turn an alert into an obligation, and who can read the audit history. RegWatch, for example, ships nine roles split across organization administration, compliance work and legal work. RBAC answers who may act; a tamper-evident audit log records what they actually did, and periodic access reviews compare the two. Buyers weighing a Private VPC deployment or a hosted service should ask how roles map to their identity provider, because access rights stay accurate only as long as the joiner, mover and leaver process behind them does.

Sources

  1. NIST Computer Security Resource Center, Role Based Access Control project accessed 30 Sep 2026

Know which changes apply to your business.

RegWatch reads the regulators you choose and explains every change it surfaces.

Book a demo