IT CanvassTalk to an advisor
Core concepts · LessonBy , SailPoint Trainer, 7 yrs · Published · IdentityIQ 8.4 · intermediate

RBAC

Role-based access control bundles entitlements into roles so access is granted by job function, not one permission at a time.

Quick answer

RBAC groups fine-grained entitlements into roles so people get access based on their job function. In IdentityIQ, business roles model job functions and contain IT roles, which bundle the actual entitlements in target systems. Assigning one business role provisions everything beneath it.

Key takeaways
  • RBAC grants access by role, not by individual permission
  • Business roles model job functions
  • IT roles bundle real entitlements in target systems
  • Roles can be assigned automatically by identity attributes
  • Good role design cuts access sprawl and review effort

Role-based access control (RBAC) is the model at the heart of SailPoint: instead of granting individual permissions, you group them into roles that map to job functions, then assign roles to people. RBAC is what makes access manageable, reviewable and provisionable at enterprise scale.

Why roles

Tracking thousands of individual entitlements per person is impossible to govern. Roles collapse that complexity into a few hundred business-meaningful units, so you reason about "Branch Teller" rather than the dozen entitlements a teller needs. Assign the role and its access follows; remove it and the access is revoked.

Business and technical roles

A common design nests two tiers: business roles model job functions and grant one or more IT/technical roles, which bundle the actual entitlements per application. This keeps the business view clean while managing technical detail underneath.

How roles are assigned

  • Automatically, via membership criteria matching identity attributes.
  • By request, from the access catalogue with approval.
  • Manually, by an administrator.

RBAC with ABAC

The strongest designs combine RBAC with attribute-based rules: identity attributes automatically drive role assignment, giving you the auditability of roles with the dynamism of attributes.

Common pitfalls

  • Over-broad roles that grant more than a job needs.
  • Role explosion, so many narrow roles they are unmanageable.
  • Unowned, unreviewed roles that drift over time.

Practice challenge

+0 XPStreak ×0
Question 1 of 3
RBAC grants access based on?

Frequently asked questions

What does the term roles & RBAC refer to in SailPoint?
Role-based access control (RBAC) is the model at the heart of SailPoint: instead of granting individual permissions, you group them into roles that map to job functions, then assign roles to people. RBAC is what makes access manageable, reviewable and provisionable at enterprise scale.
What is the practical takeaway on roles & RBAC?
Tracking thousands of individual entitlements per person is impossible to govern.
What is worth remembering about roles & RBAC in practice?
Roles collapse that complexity into a few hundred business-meaningful units, so you reason about "Branch Teller" rather than the dozen entitlements a teller needs.
What tends to go wrong with roles & RBAC?
Over-broad roles that grant more than a job needs. Role explosion, so many narrow roles they are unmanageable. Unowned, unreviewed roles that drift over time.
Want this with a live instructor and a lab tenant?
SailPoint IGA training →
Already working on SailPoint and stuck on a live ticket?Get an expert SailPoint developer on screen-share to finish your daily tasks with you. Deliver on time, protect your reputation and your job. Monthly support only, no task-wise plans.Task assigned · no idea where to startStill stuck · your job on the lineExpert joins your screenDelivered on timeExplore On Job Support