Data Rooms Providers Find a data room
VDR glossary · Permissions

What is role-based access control (RBAC)?

Definition

Role-based access control (RBAC): A permission model in which users receive rights according to their role, such as administrator, uploader or reviewer, rather than having each capability granted individually.

How it works in a data room

The platform defines a set of roles, each bundling capabilities. A typical ladder runs from full administrator, who can change settings and invite anyone, through content managers who upload and organize, to reviewers who only read what their group can see. Roles answer the question of what a user can do in the application; folder rights answer what they can see. Assigning someone to a role and to a user group together produces their full access. The data room administrator usually holds the highest role and decides who else gets elevated rights.

Why it matters in a deal

Without roles, small mistakes compound: an outside counsel accidentally able to delete files, a bidder able to see the user list. Roles keep powerful functions in a few hands and make access easier to audit. They also map neatly to security policies inside banks and corporates that require segregation of duties. For the same reason, roles support the principle of least privilege: no one gets more power than their job needs.

Example

A legal team at a US public company sets up a room for an internal investigation. Two paralegals get the content manager role so they can upload and index productions, outside counsel get reviewer rights, and only the deputy general counsel holds administrator rights. When a paralegal leaves the firm, the role is removed in one step and the record shows when. The United States guide covers related data rules.

Related terms