An authorization model where permissions are assigned to roles, and roles are assigned to users — instead of attaching individual permissions to each user, drastically simplifying access management at scale.
RBAC defines: permissions (atomic actions like 'view invoices', 'approve POs'), roles (named bundles of permissions like 'AP Clerk', 'Controller'), and assignments (which users have which roles). Adding a new hire becomes 'give them the AP Clerk role' instead of selecting 47 individual permissions. RBAC is foundational in NetSuite, Salesforce, Active Directory, and every modern SaaS. More dynamic alternatives (ABAC — Attribute-Based) add condition-based logic but at the cost of complexity.
Defining 12 standard roles in NetSuite (AP Clerk, AR Clerk, Controller, etc.) that cover 90% of users; onboarding new staff takes 5 minutes instead of an hour.
RBAC is the lowest-effort path to defensible access controls — most organizations have 10-20 distinct roles, not hundreds of individually permissioned users.
Need help implementing this in your business?
Get Started