Role-Based Access Control (RBAC)
Role-based access control (RBAC) is a way of managing permissions where each user gets a role, such as sales, accounts or admin, and each role can see and do only what that job requires. It limits damage from mistakes or misuse and is a core safeguard for personal and financial data.
Key Facts
| Typical roles | Admin, manager, staff, read-only, external partner |
|---|---|
| Controls | Which screens, records, fields and actions each role can use |
| Supports | DPDP Act security safeguards, audit requirements, separation of duties |
| Review cadence | Quarterly, plus immediately when someone changes job or leaves |
Designing roles
- List what each job needs to see and do.
- Group into as few roles as practical.
- Give the minimum access by default.
- Log sensitive actions such as exports and deletions.
Common gaps
Shared log-ins, former staff still active, and everyone given admin "for convenience". See cybersecurity basics for founder-led businesses.
Frequently Asked Questions
Is RBAC only for large companies?
No. Even a 10-person team benefits from keeping salary, bank and customer data to the people who need it.
Can roles restrict individual fields?
Yes, well-designed applications can hide fields such as cost price or phone numbers from certain roles.
Related Glossary
Need help implementing this in your business?
Turbo Bytes Consulting helps businesses streamline operations and build custom software architectures that scale without chaos.