Made in Germany
GDPR- & NIS2-compliant
25 years of IAM expertise
Vendor- & cloud-independent
Reality Check:
Why permissions get out of control without a role model
Without a clear role model, the number of access rights grows faster than anyone can keep track of.
Inconsistent assignment of rights
Two employees with identical positions have different access rights.
Overprivileged accounts
When in doubt, permissions are granted too generously.
Missing access slows down work
Essential permissions are missing, and work comes to a halt.
No answers during audits
In an audit, identifying who has access to what becomes a time-consuming investigation.

Role-Based Access Control with the IDM-Portal

Precise access rights for all identities
Every role gets exactly what it needs
In the FirstWare IDM-Portal, you define roles based on function, department or location. An administrator sees different areas than the help desk or HR. Each role is linked to exactly the permissions required for its specific task.
When an employee's position changes, their access changes automatically as well. No one keeps more permissions than their current role requires.
This also applies to location-based teams: instead of full access to the native directory, they work exclusively through the FirstWare IDM-Portal. For your central IT team, this means greater control over who can actually manage which identities.
Granular control down to the last detail
Not just whether access is granted, but exactly how it is used
RBAC in the FirstWare IDM-Portal controls far more than access alone. Using additional attribute-based rules (ABAC), you define individually for each object type what a role is allowed to do.
Creating, changing, deleting, setting group memberships or scheduling time-limited changes – each of these actions can be allowed or denied individually, independently of the others. A setup such as "may read, but not edit" is just as possible as role-dependent views within the portal itself.
This means different departments see only the data relevant to their area for the same employee.


Faster decisions
Approvals that do not have to end up with IT
The decision about a permission does not necessarily have to sit with IT. Based on roles, you define which key users or managers may approve access requests themselves, aligned with their specific area of responsibility.
Whether a new employee joins a department or an existing employee requests access to a project folder, the responsible team lead or resource owner is automatically notified by email and decides directly.
As soon as a request is approved, the permission is created automatically according to the rules defined for the relevant role.
What is the FirstWare IDM-Portal?
Flexible IAM solution for Identity Governance & Administration
The FirstWare IDM-Portal is a user-friendly IAM solution for automated provisioning and lifecycle management of all identities and groups in complex, hybrid IT landscapes.
Powered by my-IAM – the underlying technology platform that enables seamless connection of any IT systems and cloud services.

A role model for your entire IT landscape
Whether cloud-native or hybrid: your roles and permissions apply consistently across all connected systems, including Microsoft Entra ID and other directory services.
HR integration
Personio, SAP SuccessFactors, SD Worx / Loga3
Identity Providers & Directories
Microsoft Entra ID, Keycloak, hybrid infrastructures
Specialized & industry software
Dedalus Orbis, SQL integrations, CSV- & API connectors

Your benefits
Precise roles for every employee
Granular control by role and attribute
No direct system access needed
Individual views by role
Approvals by departments
Audit- and compliance-ready
Frequently Asked Questions
Frequently asked questions about Role-Based Access Control (RBAC), central role models, targeted access control and secure rights assignment with the FirstWare IDM-Portal.
What is RBAC (Role-Based Access Control)?
RBAC (Role-Based Access Control) is a model in which access rights are assigned not to individual people, but to defined roles, for example based on function, department or location. Everyone with the same role automatically receives the same permissions.
What is a role in the IDM-Portal?
A role in the FirstWare IDM-Portal defines who or what the "role holder" is allowed to manage. In concrete terms, this means which users or which specific user attributes they may manage (read, edit or delete).
Roles can be set up in different ways:
- by function (such as administrator, service desk, key user or regular employee),
- by department (such as accounting, sales or development), or
- by location (such as Dresden or Munich).
Every user needs an assigned role to be able to make any changes in the portal at all.
What is the difference between RBAC and ABAC?
RBAC assigns permissions based on a fixed role, such as department or position. ABAC (Attribute-Based Access Control) goes one step further and also takes individual attributes such as location, project assignment or contract type into account to control access rights even more granularly and dynamically. The FirstWare IDM-Portal combines both approaches: roles provide the basic structure, while attributes refine it where needed.
What is the difference between RBAC and delegation?
RBAC is the technical mechanism you use to define which role may access which data and functions. Delegation is the practical application of this mechanism to transfer specific responsibilities to departments or location-based teams.
Is implementing RBAC complex?
The initial role planning requires some preparation, but it is manageable. Our team supports you with best-practice experience from numerous projects so that your role model fits your organization from the start.
How granularly can permissions be controlled with RBAC?
Very granularly. You define not only whether a role has access, but also whether it may create, write and/or delete (among many other options), down to individual attributes and resources. Role-dependent views within the portal itself can also be controlled this way.
How does RBAC support compliance requirements?
A clear role model shows at all times, in a traceable way, who has access to what and why. This makes it much easier to comply with requirements such as GDPR, ISO 27001 or NIS-2, because permission structures can be easily demonstrated to auditors.
Let's Talk
We are here for you
Would you like to manage Role-Based Access Control securely with the FirstWare IDM-Portal?
Call us at 0 8196 - 998 4330 or use our contact form.
