Unit content
Access-control policies, roles and permissions
An access-control policy specifies which principals may perform which operations on which resources.
A simple permission can be viewed as a relation among
$$\text{principal} \times \text{resource} \times \text{operation}.$$
For example, Alice may read document A but not modify it.
Policies can be represented in several ways:
- access-control lists (ACLs) attach allowed principals or groups to a resource;
- role-based access control (RBAC) assigns permissions to roles and principals to those roles;
- capability-based designs give a principal an unforgeable reference that directly carries authority to a resource or operation.
These models organize authority differently but share the same requirement: enforcement must occur at the protected operation, not merely in navigation or presentation code.
Good authorization design also avoids unnecessary privilege. Broad roles are convenient, but every extra permission increases what a compromised account can do.