{"id":1190,"date":"2026-09-11T11:32:53","date_gmt":"2026-09-11T11:32:53","guid":{"rendered":"https:\/\/www.osto.one\/resources\/?p=1190"},"modified":"2026-09-11T11:32:53","modified_gmt":"2026-09-11T11:32:53","slug":"rbac","status":"publish","type":"post","link":"https:\/\/www.osto.one\/resources\/glossary\/rbac\/","title":{"rendered":"RBAC"},"content":{"rendered":"\n<!-- =========================================================================\n     OSTO GLOSSARY: RBAC (ROLE-BASED ACCESS CONTROL)\n     Live osto.one glossary stylesheet. Paste into one Custom HTML block. No H1.\n     ========================================================================= -->\n\n<style>\n.og{\n  --navy:#1c267a; --text:#0f1538; --muted:#0f1538; --light:#0f1538;\n  --border:#e7e9f2; --divider:#eceef5; --white:#ffffff;\n\n  --peri-50:#f4f5fd;  --peri-100:#e9ecfa; --peri-200:#cfd5f2; --peri-700:#4a52a8;\n  --sage-50:#f2f8f5;  --sage-100:#e3f0e9; --sage-200:#c3ddce; --sage-700:#3a6f5d;\n  --apri-50:#fdf6f0;  --apri-100:#fbe9dc; --apri-200:#f2cdb2; --apri-700:#a2603a;\n  --plum-50:#f8f3f9;  --plum-100:#f0e6f3; --plum-200:#dcc6e2; --plum-700:#6b4576;\n  --sky-50:#f1f7fb;   --sky-100:#e2eff7;  --sky-200:#bfd9e9;  --sky-700:#2f6a89;\n\n  --shadow:0 6px 22px rgba(15,21,56,.05);\n  --font:'Inter',-apple-system,BlinkMacSystemFont,'Segoe UI',Roboto,sans-serif;\n  font-family:var(--font); font-size:17px; line-height:1.75; color:var(--text);\n}\n.og p{margin:0 0 22px}\n.og h2{font-family:var(--font);font-size:clamp(25px,3vw,31px);font-weight:700;line-height:1.25;letter-spacing:-.5px;color:var(--navy);margin:52px 0 8px;scroll-margin-top:92px}\n.og h2::after{content:\"\";display:block;width:46px;height:5px;border-radius:3px;margin:12px 0 18px;background:var(--peri-200)}\n.og h2.c-sage::after{background:var(--sage-200)}\n.og h2.c-apri::after{background:var(--apri-200)}\n.og h2.c-plum::after{background:var(--plum-200)}\n.og h2.c-sky::after{background:var(--sky-200)}\n.og ul,.og ol{padding-left:22px;margin:0 0 24px}\n.og li{margin-bottom:9px}\n.og strong{font-weight:600}\n\n.og .dek{font-size:20px;line-height:1.6;color:var(--muted);margin:0 0 18px}\n.og .tags{margin:0 0 30px;padding:0;list-style:none;display:flex;flex-wrap:wrap;gap:8px}\n.og .tags li{margin:0}\n.og .tag{display:inline-block;font-size:12px;font-weight:600;letter-spacing:.7px;text-transform:uppercase;padding:6px 13px;border-radius:20px}\n.og .t-peri{background:var(--peri-100);color:var(--peri-700)}\n.og .t-sage{background:var(--sage-100);color:var(--sage-700)}\n\n.og .short{background:linear-gradient(135deg,var(--peri-100) 0%,var(--sage-100) 100%);border-radius:22px;padding:28px 32px;margin:0 0 30px}\n.og .short .k{font-size:13px;font-weight:700;letter-spacing:1.4px;text-transform:uppercase;color:var(--peri-700);margin:0 0 10px}\n.og .short p{font-size:19px;line-height:1.65;margin:0;color:var(--text)}\n\n.og .toc{background:var(--peri-50);border-radius:20px;padding:24px 28px;margin:0 0 34px}\n.og .toc .k{font-size:12px;font-weight:700;letter-spacing:1.3px;text-transform:uppercase;color:var(--peri-700);margin:0 0 12px}\n.og .toc ol{margin:0;padding-left:20px;columns:2;column-gap:34px}\n.og .toc li{margin-bottom:8px;break-inside:avoid;font-size:16px}\n.og .toc a{color:var(--navy);text-decoration:none;border-bottom:1px solid rgba(28,38,122,.22)}\n\n.og .callout{border-radius:4px;padding:24px 28px;margin:0 0 30px;background:var(--white);border:2px solid var(--navy)}\n.og .callout .k{font-weight:700;font-size:17px;margin:0 0 8px;color:var(--navy)}\n.og .callout p:last-child{margin-bottom:0}\n.og .callout.c-plum{background:var(--plum-50);border:none;border-radius:20px}\n.og .callout.c-plum .k{color:var(--plum-700)}\n\n.og figure{margin:0 0 30px}\n.og .sx{overflow-x:auto;-webkit-overflow-scrolling:touch;border-radius:20px;background:var(--white);box-shadow:var(--shadow)}\n.og .sx svg{display:block;width:100%;height:auto;min-width:600px}\n.og figcaption{font-size:14px;line-height:1.6;color:var(--muted);margin-top:12px}\n.og .swipe{display:none}\n\n.og table{width:100%;border-collapse:collapse;margin:0 0 28px;font-size:15px;background:var(--white);border-radius:18px;overflow:hidden;box-shadow:var(--shadow)}\n.og th{text-align:left;padding:14px 16px;font-weight:700;font-size:12.5px;letter-spacing:.8px;text-transform:uppercase}\n.og td{border-bottom:1px solid var(--divider);padding:13px 16px;vertical-align:top;line-height:1.6}\n.og tr:last-child td{border-bottom:none}\n.og .h-peri th{background:var(--peri-100);color:var(--peri-700)}\n.og .h-sage th{background:var(--sage-100);color:var(--sage-700)}\n.og .h-plum th{background:var(--plum-100);color:var(--plum-700)}\n\n.og .trio{display:grid;grid-template-columns:repeat(3,1fr);gap:14px;margin:0 0 28px}\n.og .tcard{border-radius:18px;padding:20px 22px}\n.og .tcard .n{font-size:16px;font-weight:700;margin:0 0 4px}\n.og .tcard .g{font-size:13px;font-weight:600;margin:0 0 10px;opacity:.8}\n.og .tcard p{font-size:14px;line-height:1.55;margin:0;color:var(--muted)}\n.og .tcard.a{background:var(--sky-50)}   .og .tcard.a .n,.og .tcard.a .g{color:var(--sky-700)}\n.og .tcard.b{background:var(--sage-50)}  .og .tcard.b .n,.og .tcard.b .g{color:var(--sage-700)}\n.og .tcard.c{background:var(--plum-50)}  .og .tcard.c .n,.og .tcard.c .g{color:var(--plum-700)}\n\n.og .pill{display:inline-block;font-size:11px;font-weight:700;letter-spacing:.8px;text-transform:uppercase;padding:5px 11px;border-radius:20px;white-space:nowrap}\n.og .p-req{background:var(--plum-200);color:#4d2f57}\n.og .p-exp{background:var(--sky-100);color:var(--sky-700)}\n.og .p-imp{background:#eef0f4;color:var(--muted)}\n.og .p-ask{background:var(--apri-100);color:var(--apri-700)}\n.og .p-yes{background:var(--sage-100);color:var(--sage-700)}\n.og .p-no{background:#eef0f4;color:var(--muted)}\n\n.og details{background:var(--white);border-radius:14px;margin:0 0 10px;box-shadow:0 2px 10px rgba(15,21,56,.04)}\n.og summary{cursor:pointer;padding:16px 20px;font-weight:600;font-size:17px;color:var(--navy);list-style:none;display:flex;justify-content:space-between;gap:16px;align-items:flex-start}\n.og summary::-webkit-details-marker{display:none}\n.og summary::after{content:\"+\";font-size:22px;line-height:1;color:var(--peri-700);flex:0 0 auto}\n.og details[open] summary::after{content:\"\\2013\"}\n.og details p{padding:0 20px 18px;margin:0;font-size:16px;line-height:1.7}\n\n.og .related{font-size:15px;color:var(--muted);border-top:1px solid var(--divider);padding-top:22px;margin-top:40px}\n\n@media(max-width:700px){\n  .og{font-size:16px}\n  .og .dek{font-size:18px}\n  .og .short p{font-size:17px}\n  .og .short,.og .toc,.og .callout{padding:22px 20px}\n  .og .toc ol{columns:1}\n  .og .trio{grid-template-columns:1fr}\n  .og .swipe{display:inline;font-weight:600;color:var(--peri-700)}\n  .og table{font-size:14px}\n  .og th,.og td{padding:11px 12px}\n}\n<\/style>\n\n<div class=\"og\">\n\n<p class=\"dek\">RBAC is simple to design and difficult to keep. Roles are easy to create, permissions are easy to add, and almost nothing in a growing company ever takes either of them away.<\/p>\n\n<ul class=\"tags\">\n  <li><span class=\"tag t-peri\">Glossary<\/span><\/li>\n  <li><span class=\"tag t-sage\">Access &amp; identity<\/span><\/li>\n<\/ul>\n\n<div class=\"short\">\n  <p class=\"k\">The short answer<\/p>\n  <p>RBAC stands for role-based access control. Instead of granting permissions to individual people, you attach permissions to roles and assign people to roles. Access is then decided by what someone does rather than who they are, which makes joining, moving and leaving an administrative action rather than a series of individual decisions.<\/p>\n<\/div>\n\n<p>It is the default access model in almost every system you already run, and the reason most access review findings look the way they do.<\/p>\n\n<div class=\"toc\">\n  <p class=\"k\">On this page<\/p>\n  <ol>\n    <li><a href=\"#blocks\">The four building blocks<\/a><\/li>\n    <li><a href=\"#breaks\">Where RBAC breaks<\/a><\/li>\n    <li><a href=\"#abac\">RBAC and ABAC<\/a><\/li>\n    <li><a href=\"#auditors\">What auditors check<\/a><\/li>\n    <li><a href=\"#osto\">How Osto handles RBAC<\/a><\/li>\n    <li><a href=\"#faq\">FAQ<\/a><\/li>\n  <\/ol>\n<\/div>\n\n<h2 id=\"blocks\">The four building blocks<\/h2>\n\n<figure>\n<div class=\"sx\">\n<svg viewBox=\"0 0 760 176\" xmlns=\"http:\/\/www.w3.org\/2000\/svg\" role=\"img\" aria-label=\"RBAC chain: a person is assigned a role, the role holds permissions, permissions act on resources.\">\n  <defs><marker id=\"rb\" markerWidth=\"8\" markerHeight=\"8\" refX=\"6.5\" refY=\"4\" orient=\"auto\"><path d=\"M0,0 L8,4 L0,8 z\" fill=\"#4a52a8\"\/><\/marker><\/defs>\n\n  <rect x=\"12\" y=\"30\" width=\"160\" height=\"76\" rx=\"13\" fill=\"#e2eff7\"\/>\n  <text x=\"92\" y=\"60\" text-anchor=\"middle\" font-family=\"Inter,sans-serif\" font-size=\"12.5\" font-weight=\"700\" fill=\"#2f6f96\">Person<\/text>\n  <text x=\"92\" y=\"82\" text-anchor=\"middle\" font-family=\"Inter,sans-serif\" font-size=\"10.5\" fill=\"#0f1538\">A joiner, a mover<\/text>\n  <line x1=\"176\" y1=\"68\" x2=\"196\" y2=\"68\" stroke=\"#4a52a8\" stroke-width=\"2\" marker-end=\"url(#rb)\"\/>\n\n  <rect x=\"202\" y=\"30\" width=\"160\" height=\"76\" rx=\"13\" fill=\"#cfd5f2\"\/>\n  <text x=\"282\" y=\"60\" text-anchor=\"middle\" font-family=\"Inter,sans-serif\" font-size=\"12.5\" font-weight=\"700\" fill=\"#1c267a\">Role<\/text>\n  <text x=\"282\" y=\"82\" text-anchor=\"middle\" font-family=\"Inter,sans-serif\" font-size=\"10.5\" fill=\"#0f1538\">Support agent, engineer<\/text>\n  <line x1=\"366\" y1=\"68\" x2=\"386\" y2=\"68\" stroke=\"#4a52a8\" stroke-width=\"2\" marker-end=\"url(#rb)\"\/>\n\n  <rect x=\"392\" y=\"30\" width=\"160\" height=\"76\" rx=\"13\" fill=\"#efe4f0\"\/>\n  <text x=\"472\" y=\"60\" text-anchor=\"middle\" font-family=\"Inter,sans-serif\" font-size=\"12.5\" font-weight=\"700\" fill=\"#6b4576\">Permissions<\/text>\n  <text x=\"472\" y=\"82\" text-anchor=\"middle\" font-family=\"Inter,sans-serif\" font-size=\"10.5\" fill=\"#0f1538\">Read, write, delete<\/text>\n  <line x1=\"556\" y1=\"68\" x2=\"576\" y2=\"68\" stroke=\"#4a52a8\" stroke-width=\"2\" marker-end=\"url(#rb)\"\/>\n\n  <rect x=\"582\" y=\"30\" width=\"166\" height=\"76\" rx=\"13\" fill=\"#e3f0e9\"\/>\n  <text x=\"665\" y=\"60\" text-anchor=\"middle\" font-family=\"Inter,sans-serif\" font-size=\"12.5\" font-weight=\"700\" fill=\"#3a6f5d\">Resource<\/text>\n  <text x=\"665\" y=\"82\" text-anchor=\"middle\" font-family=\"Inter,sans-serif\" font-size=\"10.5\" fill=\"#0f1538\">Records, systems, data<\/text>\n\n  <rect x=\"12\" y=\"120\" width=\"736\" height=\"42\" rx=\"13\" fill=\"#fbe9dc\"\/>\n  <text x=\"380\" y=\"146\" text-anchor=\"middle\" font-family=\"Inter,sans-serif\" font-size=\"12.5\" font-weight=\"700\" fill=\"#a2603a\">The assignment is the fourth block, and the one that decays. Roles are reviewed. Who holds them rarely is.<\/text>\n<\/svg>\n<\/div>\n<\/figure>\n\n<table class=\"h-peri\">\n  <thead>\n    <tr><th>Block<\/th><th>What it is<\/th><\/tr>\n  <\/thead>\n  <tbody>\n    <tr><td>Person<\/td><td>An employee, contractor or service account that needs to do something<\/td><\/tr>\n    <tr><td>Role<\/td><td>A named job function, defined once and reused, such as support agent or billing admin<\/td><\/tr>\n    <tr><td>Permission<\/td><td>A specific allowed action on a specific resource, attached to the role rather than the person<\/td><\/tr>\n    <tr><td>Assignment<\/td><td>The link between a person and a role, which is where most access problems actually live<\/td><\/tr>\n  <\/tbody>\n<\/table>\n\n<h2 id=\"breaks\" class=\"c-sage\">Where RBAC breaks<\/h2>\n\n<p>RBAC rarely fails at design time. It fails quietly, over about eighteen months.<\/p>\n\n<table class=\"h-sage\">\n  <thead>\n    <tr><th>Failure<\/th><th>How it happens<\/th><\/tr>\n  <\/thead>\n  <tbody>\n    <tr><td>Role explosion<\/td><td>Every exception becomes a new role. You end up with more roles than people, and nobody can say what any of them grant<\/td><\/tr>\n    <tr><td>Role creep<\/td><td>A role gains a permission to unblock one urgent task and never gives it back, so everyone holding that role silently gains it too<\/td><\/tr>\n    <tr><td>Stacked roles on movers<\/td><td>Someone changes team, gets the new role and keeps the old one. After two moves they can see more than their manager<\/td><\/tr>\n    <tr><td>Shared accounts<\/td><td>One login used by several people breaks the model entirely, because there is no person to assign a role to<\/td><\/tr>\n    <tr><td>Orphaned roles<\/td><td>A role with no members and no owner, still live, still granting access the day somebody is added to it<\/td><\/tr>\n    <tr><td>Everything in admin<\/td><td>The fastest way to ship becomes the permanent arrangement, and admin becomes the effective default role<\/td><\/tr>\n  <\/tbody>\n<\/table>\n\n<div class=\"callout\">\n  <p class=\"k\">Movers are the gap, not leavers<\/p>\n  <p>Most companies handle leavers reasonably well, because offboarding is a visible event with a checklist attached. Internal moves have no such trigger. Someone shifts from support to finance, receives the finance role on day one and keeps support access indefinitely, because nobody owns the removal. The result is an accumulation that no single decision created and no single person can explain, which is exactly what an access review is designed to surface.<\/p>\n<\/div>\n\n<h2 id=\"abac\" class=\"c-plum\">RBAC and ABAC<\/h2>\n\n<p>Attribute-based access control decides using context rather than job title: who, what, where, when and on which record.<\/p>\n\n<table class=\"h-plum\">\n  <thead>\n    <tr><th><\/th><th>RBAC<\/th><th>ABAC<\/th><\/tr>\n  <\/thead>\n  <tbody>\n    <tr><td>Decision basis<\/td><td>The role a person holds<\/td><td>Attributes of the user, resource and context<\/td><\/tr>\n    <tr><td>Example rule<\/td><td>Support agents can read tickets<\/td><td>Support agents can read tickets assigned to their own region, during their shift<\/td><\/tr>\n    <tr><td>Strength<\/td><td>Easy to explain, easy to audit, easy to grant<\/td><td>Precise, and handles cases roles cannot express<\/td><\/tr>\n    <tr><td>Weakness<\/td><td>Coarse. Exceptions turn into new roles<\/td><td>Complex. Hard to reason about and harder to evidence<\/td><\/tr>\n    <tr><td>Best for<\/td><td>Most companies, most of the time<\/td><td>Specific high-sensitivity decisions inside an RBAC model<\/td><\/tr>\n  <\/tbody>\n<\/table>\n\n<p>They are not competing models in practice. A workable pattern is RBAC as the structure, with attribute conditions applied to the handful of decisions where a role is too blunt an instrument.<\/p>\n\n<h2 id=\"auditors\" class=\"c-sky\">What auditors check<\/h2>\n\n<table class=\"h-peri\">\n  <thead>\n    <tr><th>What they ask for<\/th><th>Why it fails<\/th><\/tr>\n  <\/thead>\n  <tbody>\n    <tr><td>A list of roles and what each grants<\/td><td>Roles exist but nobody documented the permissions behind them<\/td><\/tr>\n    <tr><td>Who holds each role<\/td><td>The list includes people who moved teams or left months ago<\/td><\/tr>\n    <tr><td>Evidence of a completed access review<\/td><td>The review happened but produced no record of who approved what<\/td><\/tr>\n    <tr><td>Removals actually performed<\/td><td>The review flagged excess access and nothing was revoked afterwards<\/td><\/tr>\n    <tr><td>Separation of duties<\/td><td>One role can both raise and approve the same transaction<\/td><\/tr>\n    <tr><td>Privileged role handling<\/td><td>Administrative roles held permanently rather than elevated through <a href=\"https:\/\/www.osto.one\/resources\/glossary\/pam\/\">PAM<\/a> when needed<\/td><\/tr>\n  <\/tbody>\n<\/table>\n\n<p>The consistent theme is that a review without removals is not evidence of control. <a href=\"https:\/\/www.osto.one\/resources\/glossary\/soc-2\/\">SOC 2<\/a>, <a href=\"https:\/\/www.osto.one\/resources\/glossary\/iso-27001\/\">ISO 27001<\/a>, <a href=\"https:\/\/www.osto.one\/resources\/glossary\/pci-dss\/\">PCI DSS<\/a> and the RBI and SEBI frameworks all sample the same thing: the decision, the date and what changed as a result.<\/p>\n\n<h2 id=\"osto\">How Osto handles RBAC<\/h2>\n\n<p>Role-based access control sits inside the <a href=\"https:\/\/www.osto.one\/resources\/glossary\/iam\/\">identity and access management<\/a> module rather than as a separate product, alongside <a href=\"https:\/\/www.osto.one\/resources\/glossary\/sso\/\">single sign-on<\/a>, <a href=\"https:\/\/www.osto.one\/resources\/glossary\/mfa\/\">MFA<\/a> and <a href=\"https:\/\/www.osto.one\/resources\/glossary\/ztna\/\">private access<\/a>. Roles, assignments and the access decisions made against them are recorded in one place, which is what makes the review a report rather than an exercise in collecting spreadsheets from system owners.<\/p>\n\n<p>The part a single stack changes is the mover problem. When identity, endpoint and application events land in <a href=\"https:\/\/www.osto.one\/resources\/glossary\/siem\/\">the same SIEM<\/a>, someone holding two roles across two functions is visible as a pattern rather than as two unrelated entries in two systems. That record also answers the access control questions in <a href=\"https:\/\/www.osto.one\/resources\/glossary\/soc-2\/\">SOC 2<\/a>, <a href=\"https:\/\/www.osto.one\/resources\/glossary\/annex-a-controls\/\">ISO 27001 Annex A<\/a> and the Protect function of <a href=\"https:\/\/www.osto.one\/resources\/glossary\/nist-csf\/\">NIST CSF<\/a> from one control set.<\/p>\n\n<!-- ============ CTA ============ -->\n<div style=\"background:linear-gradient(135deg,#1c267a 0%,#3f4796 48%,#6b4576 100%);border-radius:22px;padding:38px 34px;margin:40px 0 12px;box-shadow:0 10px 26px rgba(28,38,122,.2);text-align:center;\">\n  <p style=\"display:inline-block;background:rgba(255,255,255,.16);color:#ffffff;font-family:'Inter',-apple-system,sans-serif;font-size:11px;font-weight:700;letter-spacing:1.2px;text-transform:uppercase;padding:6px 14px;border-radius:20px;margin:0 0 16px;\">Platform walkthrough<\/p>\n  <p style=\"color:#ffffff;font-family:'Inter',-apple-system,sans-serif;font-size:26px;line-height:1.3;font-weight:700;letter-spacing:-.4px;margin:0 0 12px;\">A review that produces removals<\/p>\n  <p style=\"color:#cfd3ea;font-family:'Inter',-apple-system,sans-serif;font-size:16px;line-height:1.65;margin:0 auto 26px;max-width:520px;\">Roles, assignments and access decisions in one place, with identity events correlated against endpoint and application activity. One owner, one dashboard.<\/p>\n  <a href=\"https:\/\/osto.one\/book-demo\/\" style=\"display:inline-block;background:#ffffff;color:#1c267a;font-family:&#039;Inter&#039;,-apple-system,sans-serif;font-weight:700;font-size:16px;text-decoration:none;border-bottom:none;padding:14px 32px;border-radius:12px;margin:0;\" target=\"_blank\" rel=\"noopener\"><span style=\"color:#1c267a;\">Book a demo<\/span><\/a>\n  <p style=\"color:#b3b8d8;font-family:'Inter',-apple-system,sans-serif;font-size:13px;margin:18px 0 0;\">Evidence from live controls &middot; 200+ frameworks mapped &middot; One platform, everything<\/p>\n<\/div>\n\n\n<h2 id=\"faq\">Frequently asked questions<\/h2>\n\n<details>\n  <summary>What is RBAC?<\/summary>\n  <p>Role-based access control. Permissions are attached to named roles, and people are assigned to roles rather than granted permissions individually. Access follows job function, which makes joining, moving and leaving manageable at scale.<\/p>\n<\/details>\n\n<details>\n  <summary>What is the difference between RBAC and ABAC?<\/summary>\n  <p>RBAC decides based on the role someone holds. ABAC decides based on attributes such as location, time, device or which specific record is being accessed. RBAC is easier to explain and audit. ABAC is more precise and harder to evidence. Most organisations use RBAC with a few attribute conditions layered on.<\/p>\n<\/details>\n\n<details>\n  <summary>What is role explosion?<\/summary>\n  <p>The state where every exception has been handled by creating a new role, so the organisation ends up with more roles than people and no one can say what any of them grant. It is the most common way an RBAC model becomes unmanageable.<\/p>\n<\/details>\n\n<details>\n  <summary>How is RBAC different from PAM?<\/summary>\n  <p>RBAC governs ordinary access across the organisation. <a href=\"https:\/\/www.osto.one\/resources\/glossary\/pam\/\">PAM<\/a> governs privileged access specifically, adding vaulting, approval, time-limited elevation and session recording. Administrative roles should generally be elevated through PAM rather than held permanently under RBAC.<\/p>\n<\/details>\n\n<details>\n  <summary>How often should access be reviewed?<\/summary>\n  <p>Quarterly is the common expectation, with privileged roles reviewed more frequently. What matters more than the interval is that the review produces recorded decisions and actual removals. A review with no removals reads to an auditor as a review that did not happen.<\/p>\n<\/details>\n\n<p class=\"related\"><strong>Related glossary terms:<\/strong> <a href=\"https:\/\/www.osto.one\/resources\/glossary\/iam\/\">IAM<\/a> &middot; <a href=\"https:\/\/www.osto.one\/resources\/glossary\/pam\/\">PAM<\/a> &middot; <a href=\"https:\/\/www.osto.one\/resources\/glossary\/sso\/\">SSO<\/a> &middot; <a href=\"https:\/\/www.osto.one\/resources\/glossary\/mfa\/\">MFA<\/a> &middot; <a href=\"https:\/\/www.osto.one\/resources\/glossary\/ztna\/\">ZTNA<\/a> &middot; <a href=\"https:\/\/www.osto.one\/resources\/glossary\/soc-2\/\">SOC 2<\/a> &middot; <a href=\"https:\/\/www.osto.one\/resources\/glossary\/iso-27001\/\">ISO 27001<\/a> &middot; <a href=\"https:\/\/www.osto.one\/resources\/glossary\/grc\/\">GRC<\/a><\/p>\n\n<\/div>\n","protected":false},"excerpt":{"rendered":"<p>RBAC is simple to design and difficult to keep. Roles are easy to create, permissions are easy to add, and\u2026<\/p>\n","protected":false},"author":8,"featured_media":1191,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[180],"tags":[586,588,589,587],"class_list":["post-1190","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-glossary","tag-rbac","tag-rbac-vs-abac","tag-role-explosion","tag-role-based-access-control"],"_links":{"self":[{"href":"https:\/\/www.osto.one\/resources\/wp-json\/wp\/v2\/posts\/1190","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.osto.one\/resources\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.osto.one\/resources\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.osto.one\/resources\/wp-json\/wp\/v2\/users\/8"}],"replies":[{"embeddable":true,"href":"https:\/\/www.osto.one\/resources\/wp-json\/wp\/v2\/comments?post=1190"}],"version-history":[{"count":1,"href":"https:\/\/www.osto.one\/resources\/wp-json\/wp\/v2\/posts\/1190\/revisions"}],"predecessor-version":[{"id":1192,"href":"https:\/\/www.osto.one\/resources\/wp-json\/wp\/v2\/posts\/1190\/revisions\/1192"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.osto.one\/resources\/wp-json\/wp\/v2\/media\/1191"}],"wp:attachment":[{"href":"https:\/\/www.osto.one\/resources\/wp-json\/wp\/v2\/media?parent=1190"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.osto.one\/resources\/wp-json\/wp\/v2\/categories?post=1190"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.osto.one\/resources\/wp-json\/wp\/v2\/tags?post=1190"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}