Lesson 19 / 25
RBAC, ABAC and ReBAC
Roles, attributes and relationships.
Three ways to express permissions
RBAC (role-based) assigns permissions to roles and roles to users: editor may article:update. It is easy to audit but suffers role explosion when rules depend on context. ABAC (attribute-based) evaluates rules over attributes of the subject, resource, action and environment: managers may approve expenses under 1,000 in their own department during business hours. ReBAC (relationship-based) derives access from a graph of relationships: you can view a document if you are a viewer of it, or a member of a team that is a viewer of its parent folder. Google's Zanzibar paper describes a global ReBAC system built on relationship tuples; open-source systems inspired by it include OpenFGA and SpiceDB. Real systems often mix models: roles for coarse access, relationships or attributes for fine-grained checks.
Deciding what each identity may do
Authorization ranges from simple roles to attributes and relationships, and it must be enforced on every object an API touches.
The same rule in three styles
Illustrative notation.
RBAC
role editor -> permissions [article:read, article:update]
user alice -> roles [editor]
ABAC
allow if action == "expense:approve"
and subject.role == "manager"
and subject.department == resource.department
and resource.amount < 1000
ReBAC (Zanzibar-style tuples: object#relation@subject)
folder:finance#viewer@team:accounting#member
doc:q3-report#parent@folder:finance
rule: doc viewer = direct viewer OR viewer of parent folder
check(user:alice, viewer, doc:q3-report) -> true if alice is in team accountingBadges, rules and family trees
RBAC is a building badge by job title. ABAC is a guard reading a rulebook about who, what and when. ReBAC is asking "how are you connected to this?", like being allowed into a house because you are family of the owner.
Quick check: Which model best fits Google Docs-style sharing through folders and groups?
- IP allow-listing
- Pure RBAC with global roles
- No authorization, only authentication
- ReBAC (relationship-based access control)
Answer
ReBAC (relationship-based access control) — Access is derived from relationships between users, groups, folders and documents.