RBAC, ABAC, and ReBAC each answer a different access question. Forcing one model to do every job is how you get role explosion and unexplainable entitlements.
A practical stack:
- RBAC for org responsibility (tenant admin, billing manager)
- ABAC for runtime context (environment, sensitivity, threshold)
- ReBAC for ownership, sharing, and hierarchy
Keep one enforcement call — can(principal, action, resource, context) — and let the policy plane mix models. Access reviews get easier when each entitlement maps to a clear reason.
I work at Permit.io — we wrote a decision tree for picking the stack before the next role explosion:
Top comments (0)