# ABAC (Attribute-Based Access Control)

URL: https://softwaredictionary.org/terms/abac
Category: Security
Last updated: 2026-10-06
Pronunciation: AY-back or ay-bee-ay-SEE

In short: ABAC is an authorization model that allows or denies each request by checking attributes of the user, the resource, the action and the context against policies.

## What is ABAC?

ABAC, or attribute-based access control, decides what a user may do by evaluating facts, called attributes, at the moment of each request. Attributes describe the subject, such as a user's department or clearance level; the resource, such as a document's owner or sensitivity; the action, such as read or delete; and the environment, such as the time, location or device. NIST described the model in Special Publication 800-162 in 2014.

Rules are written as policies, for example "doctors may read a patient's record if the patient is in their department and they are on shift". When a request arrives, the application, acting as a policy enforcement point, gathers the attributes and asks a policy decision point, which evaluates the policies and answers permit or deny. Policies can live in application code or in a dedicated engine such as Open Policy Agent, Amazon's Cedar or the older XML-based XACML standard, and cloud platforms such as AWS let IAM policies compare tags on users and resources.

RBAC is like a badge that opens every door of one type; ABAC is like a guard who checks your badge, the room, the time and your reason before letting you in. ABAC suits rules that depend on data, such as letting users edit only their own drafts, keeping each customer's data separate in multi-tenant software, or limiting access by country for legal reasons.

ABAC is usually compared with RBAC, role-based access control. RBAC asks only which roles a user has, while ABAC can combine any attributes, so a role becomes one attribute among many and RBAC can be seen as a special case of ABAC. The price is visibility: with RBAC, listing a role's permissions shows who can do what, but with ABAC the answer depends on data at request time, which makes audits harder. Many systems combine the two, using roles for broad access and attributes for fine-grained rules such as ownership, which also avoids the role explosion that pure RBAC can lead to.

## Key takeaways

- ABAC decides access from attributes of the user, resource, action and environment.
- Policies express rules such as "owners may edit their own drafts".
- Engines such as Open Policy Agent and Cedar evaluate policies outside app code.
- It handles fine-grained rules that would need many roles in RBAC.
- It is more flexible than RBAC but harder to audit; many systems use both.

## Example: An attribute-based policy check

```typescript
type User = { id: string; department: string; clearance: number };
type Doc = { ownerId: string; department: string; sensitivity: number; status: "draft" | "published" };

// One policy combining attributes of the user, the resource, the action and the context
function isAllowed(user: User, doc: Doc, action: "read" | "edit", now = new Date()): boolean {
  const workingHours = now.getHours() >= 8 && now.getHours() < 18;
  if (action === "read") return user.department === doc.department && user.clearance >= doc.sensitivity;
  if (action === "edit") return doc.ownerId === user.id && doc.status === "draft" && workingHours;
  return false;
}

const alice: User = { id: "u1", department: "finance", clearance: 2 };
const report: Doc = { ownerId: "u2", department: "finance", sensitivity: 2, status: "published" };
console.log(isAllowed(alice, report, "read")); // true: same department, enough clearance
console.log(isAllowed(alice, report, "edit")); // false: Alice doesn't own it
```

## Frequently asked questions

**What is the difference between ABAC and RBAC?**

RBAC grants permissions through roles such as admin or editor. ABAC evaluates attributes of the user, the resource and the context in policies, so it can express conditions such as ownership, department or time of day that roles alone can't.

**What is an example of ABAC?**

A hospital rule that lets doctors read records only for patients in their own department and only while on shift, or a document app that lets users edit only the drafts they own. Each rule combines attributes instead of naming a role.

**Which tools are used for ABAC?**

Policy engines such as Open Policy Agent, with its Rego language, and Cedar, used by Amazon Verified Permissions, as well as the older XACML standard. Cloud IAM systems also support attribute conditions, such as AWS policies based on tags.

## Sources

- [NIST SP 800-162: Guide to Attribute Based Access Control (ABAC) Definition and Considerations](https://csrc.nist.gov/pubs/sp/800/162/upd2/final)

---

Software Dictionary: https://softwaredictionary.org/ · https://softwaredictionary.org/llms.txt
