How it works
Instead of granting abilities person by person, RBAC groups them: the 'editor' role may create and edit posts, the 'viewer' role may only read, and each user gets the roles that fit their job. Changing what editors can do then means changing one role rather than hundreds of accounts. Roles are often scoped to a team or workspace, so the same person can be an admin in one organisation and a viewer in another.
Enforcement belongs on the server. A backend checks the role before acting, reading it from a table or from custom claims in the user's token, and a database can enforce it directly: PostgreSQL row level security policies can compare the user's id and role with each row. Hiding a button in the app is only cosmetic. When rules depend on relationships or attributes (the owner of this document, members of this project), finer models take over: attribute-based (ABAC) and relationship-based (ReBAC) access control, with tools such as OpenFGA.
Related terms
More in Auth and identity
Basics