Ir al contenido principal
DocumentMS

Glossary

Role-based access control

Also called: RBAC, role-based permissions

Role-based access control grants permissions to roles rather than to individuals, and assigns people to roles. In a document system it needs to be finer than read and write, because the distinction between reading a confidential document and keeping a copy of it is often the point.

Role-based access control explained

Why read and write is too coarse

A contractor reviewing a policy needs to read it and should not retain a copy. A billing clerk confirming a procedure took place needs the fact, not the clinical narrative. An auditor needs to see everything and download nothing.

None of those are expressible with two permission levels, which is why a document system needs preview-only as a distinct level from preview-and-download, and why upload-only exists for intake roles that should not be able to browse.

Where models break down

Per-document overrides. Necessary for genuine exceptions and the mechanism by which a permission model quietly unravels. The fix is not to forbid them but to surface them — a shared-access overview listing every active override and share makes them reviewable.

Role proliferation. A new role created for each exception produces dozens of near-identical roles nobody can reason about. Composing roles from permission levels per module scales better than defining new ones.

Leavers. The most common real-world failure. Single sign-on solves it structurally: a directory deactivation removes access without anyone touching the document system.

Access reviews

Whatever the model, someone has to check periodically that the assignments still reflect reality. A review is only feasible if the system can report who has access to what, which is a design requirement rather than a reporting nicety.

FAQ

Role-based access control: common questions

How many roles should we define?

Fewer than you expect — usually between five and fifteen for a mid-sized organisation. If you are creating a role per person or per exception, the model needs composing rather than extending.

Should permissions follow folders or documents?

Folders, with per-document exceptions surfaced rather than hidden. Document-level permissions as the primary model produce an estate nobody can audit.

Una sesión de 30 minutos con un ingeniero de soluciones, sobre una estructura de carpetas y una cadena de aprobación parecidas a las suyas, no un entorno de demostración genérico.