Definition
Role-based access control (RBAC) grants people permissions through roles that match their jobs, such as storekeeper or accountant, rather than configuring each person individually.
What is role-based access control used for?
An administrator defines roles with sets of permissions (view, create, approve, post) and assigns people to them. When someone changes job, you change their role. RBAC supports segregation of duties: the person who raises a purchase can’t approve it, and the person who records a goods receipt can’t post the supplier invoice. It’s often combined with record-level rules, such as salespeople seeing only their own customers.
Example: a “Buyer” role can create and issue purchase orders but can’t approve requisitions or post invoices.
Who changed what under each role is recorded in an audit trail.