Role-based access control (RBAC)

Definition

Role-based access control grants permissions to roles rather than to individuals, so a person’s access is determined by the role they hold.

It scales where per-person permissions do not, and it makes access reviewable: you can answer what a role can do without inspecting every account. Its weakness is role proliferation, where exceptions multiply until roles are per-person again by another name.