DEV Community

Auth By Example
Auth By Example

Posted on

When every exception becomes a new role, you need attributes

If your permission matrix keeps growing a new role for every customer exception, that is usually a modeling problem, not a staffing problem.

RBAC is great when access follows a stable job function: editors edit documents, admins manage the workspace. It starts to crack when the real rule is conditional. "Editors in the EU can edit GDPR-tagged docs during business hours" is not three more roles. It is a decision over user, resource, and environment attributes.

A practical test: if you cannot answer "who can access this object right now?" without inventing a role name, move that condition into attributes and evaluate it at request time. Keep roles for the coarse baseline. Put the changing facts (plan, region, classification, ownership) beside the decision, not inside another role string.

I wrote up a side-by-side of when RBAC is enough and when ABAC saves you from role explosion here: https://www.permit.io/blog/rbac-vs-abac?utm_source=devto&utm_medium=social&utm_campaign=role-explosion-means-you-need-attributes&utm_content=authbyexample

Top comments (0)