DEV Community

Auth By Example
Auth By Example

Posted on

Stop picking an authorization religion

RBAC, ABAC, and ReBAC each answer a different access question. Forcing one model to do every job is how you get role explosion and unexplainable entitlements.

A practical stack:

  • RBAC for org responsibility (tenant admin, billing manager)
  • ABAC for runtime context (environment, sensitivity, threshold)
  • ReBAC for ownership, sharing, and hierarchy

Keep one enforcement call — can(principal, action, resource, context) — and let the policy plane mix models. Access reviews get easier when each entitlement maps to a clear reason.

I work at Permit.io — we wrote a decision tree for picking the stack before the next role explosion:

https://www.permit.io/blog/fga-models-decision-tree?utm_source=devto&utm_medium=social&utm_campaign=fga-models-decision-tree&utm_content=authbyexample-article

Top comments (0)