Start with Identity
← Glossary
Concept

ReBAC

Relationship-Based Access Control. Authorization is computed by traversing a graph of relationships between subjects and resources. Popularized by Google's Zanzibar paper. Modern implementations include Authzed SpiceDB, OpenFGA, and Permify.

ReBAC fits the sharing and collaboration model most products actually have: access follows from being an owner, a member, or a parent of something, and those relationships change constantly. Zanzibar-style systems make the check fast and the graph traversable, at the cost of running a new stateful service on the request path and reasoning carefully about consistency when a permission was just revoked.

See also: fine-grained authorization, RBAC vs ABAC vs ReBAC, ABAC, authorization vendors

Related terms
Last reviewed By SWI Community TeamSuggest a correctionHow we research