Role-based access control is a way to organize the users who have access to specific information within a system. The main reason for RBAC is security and ensuring that too much information doesn’t fall into the wrong hands.
Why is RBAC Important?
RBAC protects from multiple angles at the same time. Firstly, it protects sensitive information from being exposed internally. There are two different types of internal threats: malicious and negligent. Malicious internal threats purposely look for sensitive information to exploit, while negligent internal threats leave the door open for access
RBAC in the Back Office
In the financial back office, this means that each user can only access specific information or modules that pertain to their role in the organization. RBAC limits access to sensitive data, making it more difficult to cause intentional or unintentional data loss.
For example, in a back-office onboarding workflow, different roles have access to review different parts of a vendor packet. Only those with a “legal” role will have access to update and verify the legal information from a vendor’s packet. This ensures that the people with the right knowledge access the right data.
Different Types of RBAC
There are four different types of RBAC: Core, hierarchical, constrained, and symmetric. Each has different purposes.
Core RBAC is the basis of all of the different types. It is simply the concept that users must be assigned a certain role to get access to certain information.
Hierarchical RBAC depends on your role in an organization. For example, general employees have access to a certain set of information, and managers above them get access to more, while directors above them have access to even more. There may be a point where a certain hierarchical level gets access to all information.
Constrained RBAC mainly supports separation of duties. This means that if one user approves a specific part of an invoice or vendor packet, they can’t also approve another part due to the potential conflict of interest.
Finally, symmetric RBAC is the most advanced type and is more flexible than other types. It uses role mapping to see how much information is delivered to each role and even the individual user.
Learn More
RBAC is only one of many different information control frameworks used in the financial back office. It’s important to consider which framework works best for your organization before implementing new software.
