Guide
Glossary
Role-based access control (RBAC)
Role-based access control (RBAC) is a way of managing permissions in which access is granted to roles, such as partner, solicitor, accountant or administrator, rather than to each person one by one. Staff get the access their role needs and no more, and when someone changes role or leaves, their access changes with it. RBAC applies the principle of least privilege, the same idea behind the Essential Eight strategy of restricting administrative privileges. In a well-built AI knowledge assistant, RBAC decides which documents each person can search, so the assistant only returns files the person asking could already open.
Also called RBAC, role-based permissions
Last updated:
Example
In a law firm
A 50-person law firm sets up a knowledge assistant over its precedents and matter files. The assistant follows the firm's existing roles and information barriers, so a family law solicitor cannot retrieve documents from a commercial matter they are walled off from. Precedents are open to all fee earners, while HR and partner files stay limited to those roles.
Guides that explain it in context
Secure by design. Set up correctly. Fully managed.
Talk to us before you commit to anything
Start with a free 45-minute discovery call. We look at your systems and priorities, then recommend a first step with a fixed scope, or tell you if we are not the right fit.
