[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"glossary-rbac::en":3,"gloss-cluster-rbac::en":23,"gloss-next-rbac::en":9},{"slug":4,"category":5,"name":6,"definition":7,"meta_desc":8,"faq":9,"schema_markup":9,"related":10},"rbac","security","Role-Based Access Control (RBAC)","RBAC is a permission model where you grant capabilities to roles — admin, editor, viewer — and assign users to roles, instead of attaching permissions to each person individually. A user's access is the sum of their roles' permissions, which keeps authorization manageable as your team and customer base grow. For SaaS builders, some form of RBAC is table stakes the moment customers have more than one seat: a company doesn't want every teammate able to delete the workspace or export billing data. It's also a recurring line on enterprise security questionnaires and a prerequisite for meaningful audit logs. Practical note: start simple with a few fixed roles; fully custom, granular permissions (\"resource-level\" or attribute-based access, ABAC) are far more work to build and reason about. Enforce roles on the server for every request — never rely on hiding buttons in the UI, since the API is what actually protects the data.","RBAC grants capabilities to roles and assigns users to roles, so a user's access is the sum of their roles — authorization that stays manageable as you grow.",null,[11,14,17,20],{"slug":12,"name":13},"audit-log","Audit Log (Audit Trail)",{"slug":15,"name":16},"multi-tenant","Multi-Tenant",{"slug":18,"name":19},"saml","SAML (Security Assertion Markup Language)",{"slug":21,"name":22},"scim","SCIM (System for Cross-domain Identity Management)",[24,26,30,34,37,40,43,46,49,52,55,58],{"slug":12,"category":5,"name":13,"updated_at":25},"2026-08-24T02:46:37+00:00",{"slug":27,"category":5,"name":28,"updated_at":29},"blast-radius","Blast Radius","2026-08-24T03:30:02+00:00",{"slug":31,"category":5,"name":32,"updated_at":33},"break-glass-access","Break-Glass Access","2026-08-24T02:46:38+00:00",{"slug":35,"category":5,"name":36,"updated_at":33},"bridge-letter","Bridge Letter",{"slug":38,"category":5,"name":39,"updated_at":33},"business-associate-agreement","Business Associate Agreement (BAA)",{"slug":41,"category":5,"name":42,"updated_at":25},"byok","Bring Your Own Key (BYOK)",{"slug":44,"category":5,"name":45,"updated_at":33},"cve","CVE (Common Vulnerabilities and Exposures)",{"slug":47,"category":5,"name":48,"updated_at":29},"data-classification","Data Classification",{"slug":50,"category":5,"name":51,"updated_at":33},"data-loss-prevention","Data Loss Prevention (DLP)",{"slug":53,"category":5,"name":54,"updated_at":33},"data-minimization","Data Minimization",{"slug":56,"category":5,"name":57,"updated_at":33},"data-poisoning","Data Poisoning",{"slug":59,"category":5,"name":60,"updated_at":33},"data-processing-agreement","Data Processing Agreement (DPA)"]