# RBAC, ABAC and ReBAC — Authentication & Authorization

Source: https://www.skillbyai.com/en/authentication/z-models

> Roles, attributes and relationships.

## Three ways to express permissions

**RBAC** (role-based) assigns permissions to roles and roles to users: `editor` may `article:update`. It is easy to audit but suffers **role explosion** when rules depend on context. **ABAC** (attribute-based) evaluates rules over attributes of the subject, resource, action and environment: *managers may approve expenses under 1,000 in their own department during business hours*. **ReBAC** (relationship-based) derives access from a graph of relationships: *you can view a document if you are a viewer of it, or a member of a team that is a viewer of its parent folder*. Google's **Zanzibar** paper describes a global ReBAC system built on relationship tuples; open-source systems inspired by it include OpenFGA and SpiceDB. Real systems often mix models: roles for coarse access, relationships or attributes for fine-grained checks.

## Deciding what each identity may do

Authorization ranges from simple roles to attributes and relationships, and it must be enforced on every object an API touches.

![Three ideas: RBAC, ABAC and ReBAC, enforcement in APIs, multi-tenant isolation.](assets/figures/authentication/section-7-map.svg) — Figure 7.1 — Model, decide, enforce.

## The same rule in three styles

Illustrative notation.

```text
RBAC
  role editor -> permissions [article:read, article:update]
  user alice  -> roles [editor]

ABAC
  allow if action == "expense:approve"
       and subject.role == "manager"
       and subject.department == resource.department
       and resource.amount < 1000

ReBAC (Zanzibar-style tuples: object#relation@subject)
  folder:finance#viewer@team:accounting#member
  doc:q3-report#parent@folder:finance
  rule: doc viewer = direct viewer OR viewer of parent folder
  check(user:alice, viewer, doc:q3-report)  -> true if alice is in team accounting
```

## Badges, rules and family trees

RBAC is a building badge by job title. ABAC is a guard reading a rulebook about who, what and when. ReBAC is asking "how are you connected to this?", like being allowed into a house because you are family of the owner.

**Quiz:** Which model best fits Google Docs-style sharing through folders and groups?

- [ ] IP allow-listing
- [ ] Pure RBAC with global roles
- [ ] No authorization, only authentication
- [x] ReBAC (relationship-based access control)

*Answer:* ReBAC (relationship-based access control). Access is derived from relationships between users, groups, folders and documents.
