6 Access Control

Learn how access-control policies decide who may perform which actions on resources, how common authorization models differ, and how to administer permissions securely over time.

How access decisions work

maps a subject—such as a user, program, or service—to an action on a resource, subject to applicable conditions. A permission therefore needs to be specific about both what may be done (for example, read, edit, or delete) and where that action is allowed.

is the decision to permit or deny a particular request. It is distinct from merely identifying or signing in a user: a system must also decide whether that user may perform the requested action on the particular resource.

Four ways to express access rules

models provide different ways to express access rules:

  • : Resource owners can grant or revoke access. An access-control list records which entities can access a resource and which access modes they have.

  • : A central policy governs access using classifications or labels. Users generally cannot override the policy by changing resource permissions.

  • : Permissions are assigned to roles that represent job functions, and users receive permissions through their role assignments. For example, a payroll clerk might view and update payroll records, while a payroll auditor might view them but not edit them. Role hierarchies can support inheritance, and constraints can impose restrictions such as .

  • : A policy evaluates attributes of the subject, resource, requested action, and possibly the environment. For example, a clinician might view a patient record only when assigned to that patient and using an approved device. This supports context-sensitive decisions, but the attributes and policies need careful management.

Organizations can combine models. For instance, RBAC can provide routine permissions for job functions while ABAC restricts access according to location or data sensitivity.

Limit access and divide sensitive work

The means giving users and processes only the access needed for their assigned tasks. Apply it to ordinary users, service accounts, applications, and administrators. Narrow permissions reduce the potential harm from mistakes, compromised accounts, or malicious actions.

Prefer access to a specific resource or task over broad administrator rights. Separate read, change, and delete capabilities when appropriate, and use time-limited or task-specific elevation for exceptional work. Configure systems to deny by default: access is granted only when an applicable policy explicitly allows it.

divides a sensitive process so that one person cannot complete it alone. For example, one employee may prepare a payment while another approves it. In RBAC, constraints can prevent the same user from holding or activating conflicting roles.

A practical check is to ask: Does each account have only the access needed for its current task, and are sensitive actions divided or time-limited where appropriate?

Administer access throughout its lifecycle

must be administered throughout the life of an account, not just configured once. A sound process includes:

  1. Define policy: Identify protected resources, permitted actions, roles or attributes, approval requirements, and exceptions.

  2. Provision access: Verify the business need and obtain appropriate approval before assigning an account, role, or permission.

  3. Enforce decisions: Check on every relevant request, including requests to individual records or functions—not only when a user first signs in. Deny requests that are not explicitly permitted.

  4. Review and adjust: Periodically check role assignments and permissions for unnecessary access or . Update access when a person's duties change, and promptly remove access that is no longer needed.

  5. Monitor and document: Keep records of approvals and changes, and log important access decisions so misuse or configuration errors can be investigated.

Administrative accounts need especially careful protection. Limit who can use them, restrict their privileges to necessary security functions, and review their use.

Takeaway: Define clear rules, assign only approved and necessary permissions, check each request, and regularly review and document access.