Access Control Models

RBAC vs ABAC: Choosing — and Combining — the Right Access Model

Segregation of duties only works if the underlying access model reflects how your organisation actually operates. Here's how role-based and attribute-based access control differ, and how we help organisations shape the right one.

What's the difference?

Role-Based Access Control (RBAC) grants access based on a user's role within the organisation — a "Finance Analyst" role gets a defined bundle of entitlements. It's predictable, auditable, and the right default for most of the workforce.

Attribute-Based Access Control (ABAC) grants access dynamically, evaluating attributes of the user, the resource, and the context at the moment of the request — department, clearance level, data sensitivity, location, device, time of day. It's more flexible and more precise, but harder to reason about and audit if it isn't governed properly.

In practice, mature organisations rarely pick one exclusively — segregation-of-duties (SoD) and birthright access tend to run on RBAC, while sensitive, dynamic, or highly regulated access (customer data, cross-border transfers, privileged sessions) is layered with ABAC-style conditional rules on top.

 RBACABAC
Access decided byAssigned roleUser, resource & context attributes
Best suited forStable job functions, birthright access, SoD controlDynamic, context-sensitive, or highly regulated access
AuditabilityHigh — roles map cleanly to entitlementsLower without strong policy governance
Maintenance overheadRole sprawl risk as the business changesPolicy complexity risk as rules accumulate
Typical example"Finance Analyst" role grants ERP read accessAccess granted only if department = Finance, data classification ≤ Internal, and device is managed

How IAM Tech helps

We don't start with a platform's default model — we work with your business to shape a role and policy structure that reflects how access decisions should actually be made, then implement it in the platform you run.

  • Role mining and role design workshops with business and application owners
  • Segregation-of-duties matrix design and conflict remediation
  • Hybrid RBAC + ABAC models — role-based birthright access with attribute-driven exceptions
  • Migrating organisations off ad hoc, request-based access onto a governed model
See Access Governance →

See our full approach to IAM for Aviation & Travel →

Not sure your access model reflects your business?

Take the free 2-minute IAM Health Check, or talk to us directly about role design and segregation of duties.

Talk to us