A production-quality reference for understanding modern authorization models and their practical application in real-world software systems.
This repository is designed for software developers, architects, and security engineers who want a technically accurate, framework-agnostic understanding of commonly used authorization models.
| # | Model | Abbreviation | Core Idea | Best Suited For |
|---|---|---|---|---|
| 01 | Role-Based Access Control | RBAC | Permissions are assigned to roles, and users are assigned to those roles | Organizations with well-defined roles and shared responsibilities |
| 02 | Fine-Grained Access Control | FGAC | Access is controlled at the individual resource or resource-instance level | Ownership-based access, collaboration, and resource sharing |
| 03 | Attribute-Based Access Control | ABAC | Access decisions are based on attributes of the subject, resource, action, and environment | Context-aware and dynamic authorization requirements |
| 04 | Policy-Based Access Control | PBAC | Authorization is governed by centralized, declarative policies | Enterprise systems, compliance, and multi-service architectures |
| 05 | Relationship-Based Access Control | ReBAC | Access is determined by relationships between users, resources, and other entities | Collaborative SaaS, organizations, teams, and hierarchical resources |
The repository is organized into two primary parts:
master-authentication/
β
βββ docs/
β βββ 01_Role_Based_Access_Control.md
β βββ 02_Fine_Grained_Access_Control.md
β βββ 03_Attribute_Based_Access_Control.md
β βββ 04_Policy_Based_Access_Control.md
β βββ 05_Relational_Based_Access_Control.md
β
βββ notebooks/
βββ rbac.ipynb
βββ abac.ipynb
βββ fgac.ipynb
βββ pbac.ipynb
βββ rebac.ipynb
The docs/ directory provides detailed conceptual and architectural documentation, while the notebooks/ directory provides interactive examples for exploring each authorization model.
Each authorization model follows a consistent structure to make the models easier to understand and compare.
- Overview
- Core Concepts
- How It Works
- Data Model
- Authorization Decision
- Practical Example
- Implementation Example
- Advantages
- Limitations and Trade-offs
- When to Use It
- When Not to Use It
- Comparison With Other Authorization Models
- Security Considerations
- Performance Considerations
- Testing Strategy
- Real-World Architecture
- Common Mistakes
- Summary
Each document is self-contained and introduces its model from first principles. You do not need prior knowledge of the other authorization models to follow a document.
There is no universally superior authorization model. The appropriate model depends on the structure, complexity, and context of your access requirements.
As a starting point:
Do users belong to a small number of roles with shared permissions?
β RBAC
Do users need access to specific resource instances or selectively shared resources?
β FGAC
Does access depend on subject, resource, action, or environmental attributes?
β ABAC
Should authorization rules be centrally defined and managed as policies?
β PBAC
Is access determined by relationships between users, resources, teams, or organizations?
β ReBAC
These models are not mutually exclusive. Real-world systems often combine multiple authorization strategies.
For example:
RBAC
β
Coarse-grained feature access
FGAC / ReBAC
β
Resource-level access
ABAC / PBAC
β
Context-sensitive and policy-driven decisions
The appropriate combination depends on the application's authorization requirements.
Authentication establishes who a user or system is.
Authorization determines what that authenticated identity is allowed to access or perform.
The models covered in this repository address authorization rather than authentication.
Coarse-grained authorization generally controls access at a broader resource or feature level, such as allowing an editor to access all articles.
Fine-grained authorization evaluates access at a more specific level, such as determining whether an editor can modify a particular article.
RBAC is commonly used for coarse-grained access, while FGAC, ReBAC, ABAC, and PBAC can support more detailed decisions depending on their implementation.
Some authorization decisions can remain relatively stable for a given identity and resource.
Other models can incorporate dynamic context such as:
- Time
- Location
- Network
- Resource state
- Data classification
- Device attributes
- Organizational context
ABAC and PBAC are particularly useful when authorization decisions need to incorporate such contextual information.
The notebooks/ directory contains interactive Jupyter notebooks corresponding to each authorization model.
The notebooks are intended to complement the documentation by demonstrating concepts through executable examples.
Each notebook focuses on:
- Authorization concepts
- Decision-making flows
- Practical scenarios
- Example policies or rules
- Allow and deny decisions
- Edge cases
- Security considerations
The notebooks are educational examples and are not intended to be drop-in production authorization implementations.
Parts of this repository were created with the assistance of AI language models. While the content is reviewed for technical accuracy, AI-generated material can contain mistakes, omissions, oversimplifications, or outdated information.
Authorization is a security-sensitive domain. Always validate important implementation decisions against authoritative sources and review production authorization systems with appropriate security expertise.
Contributions are welcome.
You can contribute by:
- Correcting technical inaccuracies
- Improving explanations
- Adding practical examples
- Improving notebook examples
- Adding relevant authorization models
- Improving diagrams or documentation
Before contributing, please review the Code of Conduct.
This project is licensed under the MIT License.