Attribute based access control (ABAC) decides access by comparing attributes, meaning property values, of the record with attributes of the user. Where RBAC asks "what role do you have?", ABAC asks "does this record match you?".
Why ABAC exists
RBAC works at the level of a class. It can say a clerk may open Account records, but not which accounts. When two clerks share a role but should see different rows, for example those of their own branch or country, you need a rule that looks at the data. That is ABAC.
How it works in Pega
- An Access Control Policy is defined on a class and names the action it controls, such as reading or updating.
- The policy uses a policy condition, which compares a property of the record with a property of the operator or the user's context.
- Pega applies the policy whenever it opens a record, and also when it builds lists and reports. The condition is added to the query, so users never receive rows they may not see.
Rule names and screens differ a little between versions, so check the access policy area of your own system.
RBAC, Access When and ABAC compared
| RBAC (ARO) | Access When | ABAC | |
|---|---|---|---|
| Decides by | Role and class | A condition on one record | Attributes of record and user |
| Level | Class | Record | Record and query |
| Best for | Job-based rights | Simple record checks | Row-level data protection |
A worked example
A multinational bank stores accounts for several countries in one class. Rules say that staff may only see accounts from their own country.
- Each operator has a
Countryattribute. - An access policy on the Account class says:
Account.Country = Operator.Country. - A clerk in Spain opens a list of accounts. Pega adds the country condition to the query, so only Spanish accounts appear.
- A clerk in Spain who types the ID of a German account into the URL is refused, because the policy is checked on open as well.
Tips
- Use ABAC for data isolation, and RBAC for job functions. They work best together.
- Keep policy conditions simple and based on indexed properties, so list queries stay fast.
- Test with users from different countries or branches, and test the list screens as well as direct opens.
Interview tip
Contrast it with RBAC in one line, then give the country example and mention that the condition is pushed into the database query. Related: When vs Access When and the Security label.
No comments:
Post a Comment