RBAC (role-based access control)
Role-based access control (RBAC) is an authorization model in which permissions are attached to roles, such as admin, editor or viewer, and users receive one or more roles. Instead of managing rights person by person, you manage a small set of roles and assign them. When rules depend on context, such as owning a record or belonging to a region, attribute-based access control (ABAC) or relationship-based rules complement it.
Why it matters for a PM
Permissions are a product feature that customers, especially in B2B, examine closely: who can invite users, see billing, export data or delete a workspace. A PM specifies the roles and a matrix of roles against actions, decides the defaults, and checks that the model holds up as the product grows, without an explosion of special cases.
Example
A project management tool defines four roles: owner, admin, member and guest. The matrix shows that members can create projects but not delete them, and guests see only the projects they are invited to. When a customer asks for “read-only admins”, the PM checks whether an existing role covers the need first.
Key points
- Start from actions on resources, then group them into the fewest roles that match real jobs.
- Apply least privilege: new users get the minimum access they need.
- In multi-tenant products, every check also verifies which customer the data belongs to.
- Sensitive changes, such as role updates and exports, belong in an audit log.
Common mistakes
- Creating a new role for each customer request until nobody understands the model.
- Defining roles in the interface without enforcing them in the API and the database.
- Forgetting what happens to a user's content and access when they leave the organization.
Go further with Module
The courses and lessons that cover this concept: