Precise access rights

Role-Based Access Control (RBAC)

Exactly the rights each role really needs

With Role-Based Access Control (RBAC) in the FirstWare IDM-Portal, you define via roles who may manage which users or attributes, for example by function, department or location. Anyone who wants to make changes in the portal needs an appropriate role, following the principle of least privilege.

Role-Based Access Control mit dem FirstWare IDM-Portal
Siegel Made in Germany

Made in Germany

firstware-dsgvo-nis2-konform

GDPR- & NIS2-compliant

firstware-25-Jahre

25 years of IAM expertise

Vendor- & cloud-independent_Variante B

Vendor- & cloud-independent

Quick Navi

Roles

To the role model

Granularity

To detailed control

Approvals

To approvals

Reality Check:
Why permissions get out of control without a role model

 

Without a clear role model, the number of access rights grows faster than anyone can keep track of.

Inconsistent assignment of rights

Two employees with identical positions have different access rights.

Overprivileged accounts

When in doubt, permissions are granted too generously.

Missing access slows down work

Essential permissions are missing, and work comes to a halt.

No answers during audits

In an audit, identifying who has access to what becomes a time-consuming investigation.

Without Role-Based Access Control, permissions get out of control

Role-Based Access Control with the IDM-Portal

Role-Based Access Control in the IDM-Portal – every role gets the right permissions

Precise access rights for all identities

Every role gets exactly what it needs

In the FirstWare IDM-Portal, you define roles based on function, department or location. An administrator sees different areas than the help desk or HR. Each role is linked to exactly the permissions required for its specific task.

When an employee's position changes, their access changes automatically as well. No one keeps more permissions than their current role requires.

This also applies to location-based teams: instead of full access to the native directory, they work exclusively through the FirstWare IDM-Portal. For your central IT team, this means greater control over who can actually manage which identities.

Granular control down to the last detail

Not just whether access is granted, but exactly how it is used

RBAC in the FirstWare IDM-Portal controls far more than access alone. Using additional attribute-based rules (ABAC), you define individually for each object type what a role is allowed to do. 

Creating, changing, deleting, setting group memberships or scheduling time-limited changes – each of these actions can be allowed or denied individually, independently of the others. A setup such as "may read, but not edit" is just as possible as role-dependent views within the portal itself.

This means different departments see only the data relevant to their area for the same employee.

Granulare Role-Based Access Control down to the last detail mit RBAC und ABAC
Role-Based Access Control with delegated approvals in the IDM-Portal

Faster decisions

Approvals that do not have to end up with IT

The decision about a permission does not necessarily have to sit with IT. Based on roles, you define which key users or managers may approve access requests themselves, aligned with their specific area of responsibility.

Whether a new employee joins a department or an existing employee requests access to a project folder, the responsible team lead or resource owner is automatically notified by email and decides directly.

As soon as a request is approved, the permission is created automatically according to the rules defined for the relevant role.

What is the FirstWare IDM-Portal?

Flexible IAM solution for Identity Governance & Administration

 

The FirstWare IDM-Portal is a user-friendly IAM solution for automated provisioning and lifecycle management of all identities and groups in complex, hybrid IT landscapes.

Powered by my-IAM – the underlying technology platform that enables seamless connection of any IT systems and cloud services.

Flexible IAM solution for Identity Governance & Administration

A role model for your entire IT landscape

 
Whether cloud-native or hybrid: your roles and permissions apply consistently across all connected systems, including Microsoft Entra ID and other directory services.

N

HR integration

Personio, SAP SuccessFactors, SD Worx / Loga3

N

Identity Providers & Directories

Microsoft Entra ID, Keycloak, hybrid infrastructures

N

Specialized & industry software

Dedalus Orbis, SQL integrations, CSV- & API connectors

FirstWare IDM-Portal: IAM solution for Identity Governance in hybrid IT landscapes

Your benefits

Precise roles for every employee

Precise roles for every employee

Role-Based Access Control with approvals by departments

Granular control by role and attribute

No direct system access needed

No direct system access needed

Individual views by role

Individual views by role

Approvals by departments

Approvals by departments

Audit- and compliance-ready Role-Based Access Control

Audit- and compliance-ready

Frequently Asked Questions

Frequently asked questions about Role-Based Access Control (RBAC), central role models, targeted access control and secure rights assignment with the FirstWare IDM-Portal.

What is RBAC (Role-Based Access Control)?

RBAC (Role-Based Access Control) is a model in which access rights are assigned not to individual people, but to defined roles, for example based on function, department or location. Everyone with the same role automatically receives the same permissions.

What is a role in the IDM-Portal?

A role in the FirstWare IDM-Portal defines who or what the "role holder" is allowed to manage. In concrete terms, this means which users or which specific user attributes they may manage (read, edit or delete). 

Roles can be set up in different ways:

  • by function (such as administrator, service desk, key user or regular employee),
  • by department (such as accounting, sales or development), or
  • by location (such as Dresden or Munich).

Every user needs an assigned role to be able to make any changes in the portal at all.

What is the difference between RBAC and ABAC?

RBAC assigns permissions based on a fixed role, such as department or position. ABAC (Attribute-Based Access Control) goes one step further and also takes individual attributes such as location, project assignment or contract type into account to control access rights even more granularly and dynamically. The FirstWare IDM-Portal combines both approaches: roles provide the basic structure, while attributes refine it where needed.

What is the difference between RBAC and delegation?

RBAC is the technical mechanism you use to define which role may access which data and functions. Delegation is the practical application of this mechanism to transfer specific responsibilities to departments or location-based teams.

Is implementing RBAC complex?

The initial role planning requires some preparation, but it is manageable. Our team supports you with best-practice experience from numerous projects so that your role model fits your organization from the start.

How granularly can permissions be controlled with RBAC?

Very granularly. You define not only whether a role has access, but also whether it may create, write and/or delete (among many other options), down to individual attributes and resources. Role-dependent views within the portal itself can also be controlled this way.

How does RBAC support compliance requirements?

A clear role model shows at all times, in a traceable way, who has access to what and why. This makes it much easier to comply with requirements such as GDPR, ISO 27001 or NIS-2, because permission structures can be easily demonstrated to auditors.

Let's Talk

We are here for you

 

Would you like to manage Role-Based Access Control securely with the FirstWare IDM-Portal?

Call us at 0 8196 - 998 4330 or use our contact form.