{
  "id": 10612549,
  "title": "When every exception becomes a new role, you need attributes",
  "url": "https://urgent.news/2026/09/29/when-every-exception-becomes-a-new-role-you-need-attributes",
  "topic": "tech",
  "section": "Tech",
  "published": "2026-09-29T05:09:12.000Z",
  "source": {
    "name": "Dev.to",
    "slug": "dev-to",
    "url": "https://dev.to/authbyexample1/when-every-exception-becomes-a-new-role-you-need-attributes-3911"
  },
  "original_language": "en",
  "account": "When a permission matrix begins to grow a new role for every customer exception, that is typically a modeling issue, not a staffing problem. Role-Based Access Control (RBAC) is effective when access follows a consistent job function, such as editors editing documents and administrators managing the workspace. However, when the real rule is conditional, RBAC begins to break down. For example, editors in the European Union (EU) who can edit GDPR-tagged documents only during business hours should not require three additional roles. Instead, it's a matter of evaluating user, resource, and environment attributes. To determine who can access a particular object at any given moment, one should not need to invent a new role name. Instead, these conditions should be moved to attributes and evaluated at request time. Roles should be reserved for the broad base, while the changing facts (such as plan, region, classification, and ownership) should be placed beside the decision, not within another role string.",
  "summary": "If your permission matrix keeps growing a new role for every customer exception, that is usually a modeling problem, not a staffing problem. RBAC is great when access follows a stable job function: editors edit documents, admins manage the workspace. It starts to crack when the real rule is conditional. \"Editors in the EU can edit GDPR-tagged docs during business hours\" is not three more roles.…",
  "key_points": [
    "Role-based access control breaks down with conditional rules.",
    "User, resource, and environment attributes evaluate access.",
    "Roles reserved for broad base, attributes for changing facts."
  ],
  "editors_take": "Shifting conditional access rules from roles to attributes allows for more flexible and dynamic access control, reducing the need for proliferating new roles to accommodate exceptions.",
  "illustration": null,
  "coverage": {
    "outlets": 1,
    "also_reported_by": []
  },
  "ai_generated": true,
  "disclaimer": "Summaries, key points and the editor’s take are written by software from other outlets’ reporting and may contain errors — always check the linked original."
}