| name | design-role-based-access-control |
| category | code |
| description | Design role-based access control from explicit resources, actions, constraints, and ownership. Use when permissions have outgrown scattered conditionals or informal administrator conventions. |
design-role-based-access-control
Make authorization decisions predictable, reviewable, and enforced at every trusted entry point.
Procedure
- Inventory protected resources, actions, data scopes, environments, and consequential side effects.
- Model permissions as verb-and-resource grants with explicit tenant, ownership, or state constraints.
- Derive a small role set from stable job responsibilities, not from individual people.
- Default to deny and define precedence for grants, restrictions, separation of duties, and emergency access.
- Put authorization enforcement in a shared server-side decision point near the protected operation.
- Design assignment, approval, expiry, review, transfer, and revocation workflows with named owners.
- Produce a decision matrix covering role, action, resource relationship, condition, and expected result.
- Test direct requests, alternate routes, bulk actions, background jobs, exports, and cross-tenant references.
- Log consequential assignments and decisions without exposing sensitive resource data.
- Migrate existing permissions with comparison mode, exception tracking, and a rollback point.
Guardrails
- UI visibility is not an authorization boundary.
- Do not create one-off roles whenever a user requests a single exception.
- Never let an untrusted client choose its own role, tenant, or resource ownership.
Done
- An approved permission model and role-assignment workflow are documented
- The decision matrix is tested across every trusted entry point
- Existing and new authorization results are reconciled before enforcement