All glossary terms
PGlossary

Policy-Based Access Control

Policy-based access control is an approach in which centrally defined rules determine whether access should be granted or retained.

Policy-based access control is an approach in which centrally defined rules determine whether access should be granted or retained. Policies can evaluate roles, attributes, relationships, resource sensitivity, risk, time and other context.

ABAC and RBAC can both operate within a policy-based approach. In IGA, policy also governs eligibility, approvals, duration, review frequency and remediation—not only runtime authorization.