Skip to main content

RBAC

Role‑based access control (RBAC) ensures that only authorized users can change policies or view sensitive findings.

Typical Roles

Many organizations define roles such as:

  • Policy authors – create and modify policies and policy packs; limited to specific domains where possible.
  • Compliance and security owners – approve new controls, review exceptions, and oversee posture.
  • Operators – run evaluations, manage schedules, and coordinate remediation.
  • View‑only consumers – application owners, auditors, and stakeholders who view dashboards and reports but cannot change policies.

These roles can be implemented using Cloudaware permission sets and profiles.

Principles

When configuring RBAC:

  • Apply the principle of least privilege—only grant policy modification rights to users who need them.
  • Separate policy design from policy enforcement where appropriate.
  • Ensure auditors have read‑only access to findings, exceptions, and evidence.

Well‑designed RBAC reduces the risk of unintended policy changes and improves auditability.