ReBAC
Relationship-Based Access Control. Authorization is computed by traversing a graph of relationships between subjects and resources. Popularized by Google's Zanzibar paper. Modern implementations include Authzed SpiceDB, OpenFGA, and Permify.
ReBAC fits the sharing and collaboration model most products actually have: access follows from being an owner, a member, or a parent of something, and those relationships change constantly. Zanzibar-style systems make the check fast and the graph traversable, at the cost of running a new stateful service on the request path and reasoning carefully about consistency when a permission was just revoked.
See also: fine-grained authorization, RBAC vs ABAC vs ReBAC, ABAC, authorization vendors
Related on Start with Identity
- GlossaryRBAC
Role-Based Access Control. Permissions are bundled into roles, users are assigned roles. Simple to understand and audit, but role explosion is a common failure
- GlossaryRole Mining
Analyzing existing access to discover sensible roles, reducing role explosion and cleaning up entitlements. A common step in rolling out or fixing RBAC. Role mi
- GlossaryAccess Certification
Periodic review of who has access to what, with managers or resource owners attesting that access is still appropriate. A regulatory requirement in many industr
- GuideFrom RBAC to ReBAC: when and how to migrate
RBAC is great until your customers need to share individual resources, not entire roles. The moment you find yourself adding a 50th role named like `editor_for_