Lesson 19 / 25

RBAC, ABAC and ReBAC

Roles, attributes and relationships.

Three ways to express permissions

RBAC (role-based) assigns permissions to roles and roles to users: editor may article:update. It is easy to audit but suffers role explosion when rules depend on context. ABAC (attribute-based) evaluates rules over attributes of the subject, resource, action and environment: managers may approve expenses under 1,000 in their own department during business hours. ReBAC (relationship-based) derives access from a graph of relationships: you can view a document if you are a viewer of it, or a member of a team that is a viewer of its parent folder. Google's Zanzibar paper describes a global ReBAC system built on relationship tuples; open-source systems inspired by it include OpenFGA and SpiceDB. Real systems often mix models: roles for coarse access, relationships or attributes for fine-grained checks.

Deciding what each identity may do

Authorization ranges from simple roles to attributes and relationships, and it must be enforced on every object an API touches.

Three ideas: RBAC, ABAC and ReBAC, enforcement in APIs, multi-tenant isolation.
Figure 7.1 — Model, decide, enforce.

The same rule in three styles

Illustrative notation.

RBAC
  role editor -> permissions [article:read, article:update]
  user alice  -> roles [editor]

ABAC
  allow if action == "expense:approve"
       and subject.role == "manager"
       and subject.department == resource.department
       and resource.amount < 1000

ReBAC (Zanzibar-style tuples: object#relation@subject)
  folder:finance#viewer@team:accounting#member
  doc:q3-report#parent@folder:finance
  rule: doc viewer = direct viewer OR viewer of parent folder
  check(user:alice, viewer, doc:q3-report)  -> true if alice is in team accounting

Badges, rules and family trees

RBAC is a building badge by job title. ABAC is a guard reading a rulebook about who, what and when. ReBAC is asking "how are you connected to this?", like being allowed into a house because you are family of the owner.

Quick check: Which model best fits Google Docs-style sharing through folders and groups?

  • IP allow-listing
  • Pure RBAC with global roles
  • No authorization, only authentication
  • ReBAC (relationship-based access control)
Answer

ReBAC (relationship-based access control) — Access is derived from relationships between users, groups, folders and documents.