# Role Based Access Control Rbac
**Source:** https://glossary.keenfunnel.com/terms/role-based-access-control-rbac
**Language:** German

---

## Technische Erklärung

RBAC separates users, roles, permissions, sessions, and constraints. Role hierarchies can inherit permissions, while separation-of-duty rules prevent conflicting assignments or activations. Roles should reflect stable job responsibilities and be governed through approval and review.

## Geschäftliche Relevanz

RBAC simplifies permission administration at scale, supports least privilege, and provides an auditable connection between job responsibilities and system access.

## Implementierungsbeispiel

A finance-analyst role can view invoices and reports, while a payment-approver role can authorise payments. Separation-of-duty rules prevent one user from holding both capabilities without exception approval.

## Einschränkungen und häufige Missverständnisse

Poor role design causes role explosion or excessive access. RBAC handles contextual and fine-grained decisions less naturally than attribute-based approaches and still requires lifecycle management and access reviews.

## Themen

Cybersicherheit Systemarchitektur

## Quellen

NIST — Role Based Access Control — NIST IR 6192 — https://csrc.nist.gov/pubs/ir/6192/final

## Besprechen Sie Ihre Systeme

Benötigen Sie Hilfe bei der Implementierung oder Bewertung dieses Konzepts? Keenfunnel entwirft vernetzte KI-, Automatisierungs- und Datensysteme.

Discovery-Session buchen