Skip to content
Insights
Request Services
Relationship-Based Access Control (ReBAC)
All IAM glossary termsAuthorization · glossary

Relationship-Based Access Control (ReBAC)

Definition

Relationship-Based Access Control (ReBAC) is an authorization model based on graph-style relationships between users and resources — popularized by Google's Zanzibar and implementations like SpiceDB, OpenFGA, and Auth0 FGA.

In more depth

ReBAC models authorization as a graph: "user U is a viewer of document D because U is a member of group G which has viewer permission on D." Access checks traverse the relationship graph. This is particularly natural for collaboration software where access flows through nested groups, shared folders, project membership, etc.

Zanzibar (Google's internal system) was the inspiration. Modern open-source implementations include SpiceDB (AuthZed), OpenFGA (Auth0), and Topaz. ReBAC complements RBAC + ABAC; it's especially good when authorization depends on nested relationships that change frequently.

Related terms
  • Role-Based Access Control (RBAC) · Authorization
  • Attribute-Based Access Control (ABAC) · Authorization
  • OPA (Open Policy Agent) · Authorization
  • PDP (Policy Decision Point) · Authorization
Want the work, not just the definition?

We staff + deliver across IAM.

Talk to a practice leadMore glossary terms

Identity, cybersecurity, and custom software for regulated enterprises. Audit-ready operations from advisory through audit.

Americas HQ

Wilmington, DE

America/New York

India HQ

Hyderabad, TG

Asia/Kolkata

Services
  • IAM Consulting
  • IAM Technologies
  • Custom Software & AI
  • IAM Staffing
  • Request Services
  • Case Studies
Resources
  • All Resources
  • Complete Guide to IAM
  • IAM Frameworks Compared
  • IAM Certification Roadmap
  • IAM API Hub
  • IAM Explainers
  • IAM Vendor Status
  • Release Notes
  • State of Identity
  • State of PAM
  • State of IGA
  • State of CIAM
  • State of AI Agent Identity
  • IAM Salary Benchmark
  • Vendor Pricing Index
  • Year in Review 2026
  • Acquisition Tracker
  • Outage Tracker
  • Identity Incidents
  • Vulnerability Tracker
  • Cheat Sheets
  • Standards Explainers
  • Migration Playbooks
  • Audit Checklists
  • Reference Architectures
  • RFP Templates
  • IAM Anti-Patterns
  • Compliance Crosswalk
  • Market Landscape
  • Awesome IAM
  • IAM Glossary
  • Compliance Frameworks
  • Integration Guides
  • Vendor Alternatives
  • IAM by Industry
  • Salary Lookup
  • Directory
Research & media
  • IAM Compensation 2026
  • Vendor Moves Q3 2026
  • Identity Incidents Q3 2026
  • Vendor Security Posture 2026
  • Vendor Pricing 2026
  • AI Citation Tracker
  • Top 50 IAM Tools 2026
  • Podcast
  • Videos
  • Newsletter
  • Newsletter Archive
  • Embed Widgets
Free tools
  • JWT Decoder
  • JWT Signer
  • SAML Decoder
  • SAML Metadata Diff
  • OAuth Flow Visualizer
  • OIDC Debugger
  • OIDC Discovery Validator
  • PKCE Generator
  • WebAuthn Tester
  • Bearer Token Inspector
  • SCIM Validator
  • Password Entropy
  • IAM RFP Template
  • PAM Vendor Selector
  • Maturity Assessment
  • ROI Calculator
  • TCO Calculator
  • MFA Bypass Risk
  • Audit-Prep Burden
  • Quizzes
Company
  • About
  • Leadership
  • Approach
  • Why Choose Us
  • Partners
  • Press Kit
  • Press Topics
  • Global Presence
  • Locations
  • Insights
  • Now
  • Community
  • Open Roles
  • Submit Resume
  • Training
  • Contact

© 2026 askmeidentity, Inc.. Safeguard your digital frontier.

  • Privacy Policy
  • Terms of Service
  • Accessibility