Security
Part 2 of 6 · AuthorizationRBAC — Roles, Permissions & Role Explosion
Roles, permissions, and how role explosion pushes teams toward ABAC/ReBAC.
- 1Gist
- 2Maps
- 3Q&A
- 4Sandbox
Voice readout needs Web Speech Synthesis in this browser.
Persona roles vs a role per object
Prefer
Persona-sized roles plus a later model
support, engineer, and billing stay in the catalog. Ownership and shares move to attributes or tuples when they show up.
- Effective permissions stay explainable.
- Separation of duties is a pair of roles, not a spreadsheet of exceptions.
- A new tenant does not mint a new global role name.
Alternative
admin_acme, doc_editor_123, and clones
Every ticket becomes a role. The matrix is the product, and nobody can say what an assignment means.
- Revoke is a scavenger hunt through near-duplicates.
- SoD conflicts hide inside copied grants.
- The interview name for this is role explosion.
Check path
Identity already exists. This is only the role expansion.
- 1
Load assignments
The subject holds roles, sometimes scoped to a tenant. IdP groups often sit in front of the role. - 2
Close the hierarchy
admin inherits editor inherits viewer. Walk the edges before you union permissions. - 3
Refuse a broken SoD set
submitter and approver together never authorize, even if each permission would have matched. - 4
Allow only on catalog hit
The required permission is in the expanded set, or the answer is deny.
Overview
Almost every codebase starts with user.role == "admin". That works until the catalog is admin_acme, admin_globex, and doc_editor_123, plus a spreadsheet of exceptions. Interviews ask you to name role explosion, to show hierarchy or a scoped assignment, and to know when the next lesson is ABAC or ReBAC.
Who holds the session stays in OAuth & OIDC — Authorization Code + PKCE. This page only assigns and evaluates roles after that subject id exists.
Core model
- Permission — an atomic capability, such as
orders:refundordocs:write. - Role — a named bundle (
support_agent,billing_admin). - Assignment — a user or service holds one or more roles, sometimes scoped to a tenant.
- Session activation — optional NIST idea: which of the assigned roles are active for this session.
Flow
- 1
1. Subject is known
- next2. Load role assignments
- 2
2. Load role assignments
- next3. Expand to permissions
- 3
3. Expand to permissions
- next4. Refuse SoD conflicts
- 4
4. Refuse SoD conflicts
- next5. Allow only on catalog hit
- 5
5. Allow only on catalog hit
Lesson map
RBAC — Roles, Permissions & Role Explosion
Roles, permissions, and how role explosion pushes teams toward ABAC/ReBAC.
Architecture. Architecture
Select a node to see why it exists, or an edge to see the protocol, direction, effect, and consequence.
Mermaid export
flowchart TB a["1. Subject is known"] b["2. Load role assignments"] c["3. Expand to permissions"] d["4. Refuse SoD conflicts"] a -->|1. Subject is known| b b -->|2. Load role assignments to| c c -->|3. Expand to permissions to| d
Hierarchical RBAC speeds assignment and complicates revocation. You have to answer "which inherited edge still grants this?" Separation of duties makes some roles mutually exclusive: payment_submitter and payment_approver must not land on the same subject. Enforce that when you write the assignment and again when you authorize, in case a bad row already exists. Least privilege prefers task roles over god-roles, and time-boxes elevation.
Variants
| Approach | Pros | Cons | Use when |
|---|---|---|---|
| Flat roles | Simple UI | Coarse; duplicate grants | Early product; few personas |
| Hierarchical RBAC | One senior role instead of many | Inheritance surprises | Stable org charts |
| Scoped roles | admin at a tenant, not N global roles | Still explodes if the scope is a resource id | Multi-tenant coarse admin |
| Per-resource roles | Looks precise | Classic role explosion | Stop. Prefer ReBAC or ABAC |
Scoped assignment is "Alice is admin of tenant Acme." Encoding admin_acme into the role string is a naming hack. It still explodes, and every service parses names differently.
Role explosion
Symptoms: roles named after tickets; a role per folder or document; a permission matrix nobody can explain; copy-paste clones per customer.
Fixes:
- Keep roles persona-sized: support, engineer, billing.
- Move resource ownership to ReBAC or an
owner_idattribute on the ABAC page. - Use attributes for environment and risk instead of
admin_after_hours. - Centralize the permission catalog. Forbid ad-hoc string checks that invent a new permission in one service.
Sandbox: expand roles and refuse SoD
Editor inherits viewer. Admin inherits editor. Submitter and approver together are a hard deny, even though each role has a real permission.
Press Run. Snippets must be self-contained — no network, files, or native modules.
Press Run. Snippets must be self-contained — no network, files, or native modules.
The TypeScript snippet is a flat union, no hierarchy. That is honest: if you need inheritance, you have to code the closure, as in the Python sandbox, or you will explain the wrong effective set in an incident.
Interview Q&A
What is the RBAC triple?
Answer
A subject is assigned roles. Roles grant permissions. Authorization checks whether the required permission is in the subject's expanded set. If a hierarchy exists, expand it before the check.
What is role explosion?
Answer
A proliferation of near-duplicate or per-resource roles until the catalog is unmaintainable. It is the signal to move instance-level access to attributes or relationships.
How do hierarchical roles help and hurt?
Answer
Help: assign one senior role instead of many. Hurt: accidental privilege through deep inheritance, harder "effective permissions" explanations, and revokes that must consider the graph.
What is separation of duties?
Answer
A rule that certain role combinations must not be held by the same subject, for example create versus approve payment. Enforce it when you write the assignment and again at request time.
Are OAuth scopes RBAC?
Answer
Scopes are a coarse capability list granted to a client. They are related to permissions and they are not an application role catalog. Resource checks still belong in the API. Issuance of those scopes stays on the OAuth and OIDC pages.
When do you leave pure RBAC?
Answer
"User may edit only their rows," share graphs, time or risk conditions, or a multi-tenant admin that would require thousands of roles. Persona roles can stay. The instance check moves.
How do you audit RBAC?
Answer
Who has which role, who granted it, an effective-permissions report, an SoD conflict report, and periodic access review for privileged roles. Group-to-role indirection belongs in that report or you will debug the wrong layer.
What is session activation?
Answer
NIST RBAC lets a subject hold roles that are not all active in this session. A break-glass admin role can be assigned and still inactive until a time-boxed elevation. The check uses the active set, not the dusty assignment alone.
Why a permission catalog instead of role-string checks?
Answer
role == "admin" scattered through services invents a new meaning of admin in each repo. A catalog gives one name for doc:share, one owner, and a test that viewer does not have it.
Pitfalls
List five role names you would reject in review. For each, say whether the fix is a scoped persona, an owner attribute, or a relationship tuple. Then name one SoD pair you would refuse to assign together.