Attribute Based Access Control (ABAC) vs Role Based Access Control (RBAC)

ABAC vs RBAC

ABAC vs RBAC

Attribute Based Access Control (ABAC) and Role Based Access Control (RBAC) are similar in that they both seek to control data access based on the business reasons why a person should receive access, rather than simply a list of people.

RBAC is simpler than ABAC. It is essentially the same idea, but it is one-dimensional. For example, it can grant access to ‘Role=Manager’, but the rule can’t be made more specific using a second dimension, as in ‘Role=Manager and Office=Paris’. ABAC can include theoretically as many dimensions as needed.

Without the additional power of ABAC, organisations typically either tolerate access being widely and inaccurately available to people who shouldn’t have it, or revert back to using manual lists-based access.

The ABAC based Torsion approach

Torsion’s ABAC is highly flexible, to fully embrace the complexity that happens when real-world organisations use Microsoft 365.

‘Pure ABAC’ assumes the organisational structure is rigid and consistent. A rule like ‘Role=Manager and Office=Paris’ assumes that everybody has exactly one role and one office. But what about when someone goes on vacation, and somebody covers for them? Or when somebody changes roles, starts their new role, but also still continues in their old role during a handover to their replacement? When it comes to collaboration, people work in multiple situations all the time.

Torsion’s accommodates temporary or permanent periods where a user may have multiple roles, assignments or circumstances (such as holiday cover, handover periods etc) and gradually ‘decays’ temporary or expiring access, resulting in access control that more accurately represents the fluid realities of organisational structures.

Torsion delivers on the promise of ABAC, within the unique constraints and requirements of Microsoft 365 collaboration systems.

Why Torsion

Torsion delivers powerful visibility and control of ‘who has access to what’ in Microsoft 365.

Torsion seamlessly empowers data owners to take responsibility for their own data, because they understand their data best. Its 360-degree visibility and round-the-clock audit trail effortlessly satisfies compliance. And its intelligent automation eliminates inappropriate permissions throughout your data at massive scale, in real time, on auto-pilot.

Fully automated with rapid value in mind, Torsion is quick and easy to deploy, and needs little or no user training. Data owners own the decisions which make sense for them, saving IT precious time whilst maintaining oversight.

Torsion is crafted to be simple, intelligent and effortless for business users, not just IT. It’s trustworthy Data Access Governance for security and compliance, so you can unleash collaboration.

Imagine a world where users can collaborate freely, data access is under control, compliance is a breeze, and the whole thing runs itself. It’s how we bring the phrase, ‘collaborate without limits’ to life.

Torsion. Collaborate without limits.