Role based access control (RBAC) is the basic way Pega decides what a signed-in person may do. Instead of granting rights to each person, you grant them to roles, and you put people into roles through their access group. Change the role once and everyone who uses it is updated.
The chain of rules
- Operator ID: the person's account.
- Access Group: says which application the operator works in and which roles they have.
- Access Role Name: a named role such as
Bank:Clerk. - Access of Role to Object (ARO): what the role may do to records of a class.
- Privilege: a named permission that guards a specific action, such as approving a loan.
- Access Deny: an explicit refusal that overrides grants.
A role can also be built on another role and inherit its rights, which helps you avoid repeating yourself.
What RBAC can and cannot do
- It can say: "Clerks may update Loan cases."
- It cannot easily say: "Clerks may update only the loans in their own branch." That needs record-level rules, either an Access When on the ARO or attribute based access control (ABAC).
A worked example
A bank needs three types of user on its loan application:
| Person | Access group | Role | What they can do |
|---|---|---|---|
| Priya, clerk | Bank:Clerks | Bank:Clerk | Create and update loans |
| Marco, manager | Bank:Managers | Bank:Manager (built on Clerk) | Everything a clerk can do, plus approve loans through the ApproveLoan privilege |
| Ada, auditor | Bank:Auditors | Bank:Auditor | Open loans and run reports, but never update |
When the bank later allows clerks to run a monthly report, the change is one ARO on the Clerk role, and Priya and every other clerk gets it.
Good practice
- Design roles around job functions, not individuals.
- Give the least access needed, and add rights only when a real need appears.
- Review who is in each access group regularly.
- Test every role with a real operator ID.
Interview tip
Draw the chain from operator to access group to role to ARO, then explain the limit of RBAC and how ABAC or Access When fills the gap. Related: Access of Role to Object, Access Deny and What is Security in Pega?
No comments:
Post a Comment