AuthZ models: RBAC, ABAC, ReBAC
P56.access-models.01 · Audience: guest, it-ml, language-pro · Prerequisites: Passwords done right
Welcome to IAM & Authorization — the last pillar of the Authentication & Identity domain. P54 and P55 established who you are; authorization decides what you may do. This track builds the two most common models: RBAC (roles grant permissions) and ABAC (attribute conditions on top), both anchored on the golden rule — deny by default.
Same thread as every module here: concept → protocol → attack → defence. The graded work is always the defence — here, refusing anything not explicitly granted.
The code runs entirely in your browser (Pyodide); nothing leaves your machine.
Ask the mentor about this module
Ask a question about this content. The mentor explains and grounds its answer in what you are studying; asking is recorded as a learning signal, not a grade.
Keeping your files on this device
Off by default. The mentor always gets your file; this only decides whether your own copy stays here. Copies live in this browser only - they do not follow you to another device, and clearing site data removes them.
Rung 1 — RBAC: a role-based access check
Loading exercise…
Rung 2 — ABAC: add attribute rules
Loading exercise…
My notes on this module
Loading your notes...
Where next?
This module unlocks
Go up a level