---
title: "Relationship-Based Access Control — Identity Glossary |…"
description: "ReBAC models authorization as a graph of relationships — *user is editor of document, document is in folder, folder belongs to team* — making it ideal for…"
lang: en
json-ld: |
  [
    {
      "@context": "https://schema.org",
      "@type": "BreadcrumbList",
      "itemListElement": [
        {
          "@type": "ListItem",
          "position": 1,
          "name": "Home",
          "item": "https://idsync.com/"
        },
        {
          "@type": "ListItem",
          "position": 2,
          "name": "Glossary",
          "item": "https://idsync.com/glossary"
        },
        {
          "@type": "ListItem",
          "position": 3,
          "name": "Relationship-Based Access Control",
          "item": "https://idsync.com/glossary/relationship-based-access-control"
        }
      ]
    },
    {
      "@context": "https://schema.org",
      "@type": "DefinedTerm",
      "@id": "https://idsync.com/glossary/relationship-based-access-control",
      "name": "Relationship-Based Access Control",
      "alternateName": [
        "ReBAC",
        "ReBAC",
        "Zanzibar"
      ],
      "description": "ReBAC models authorization as a graph of relationships — *user is editor of document, document is in folder, folder belongs to team* — making it ideal for collaborative products like Google Docs, Notion, GitHub, and Figma.",
      "url": "https://idsync.com/glossary/relationship-based-access-control",
      "inDefinedTermSet": "https://idsync.com/glossary"
    },
    {
      "@context": "https://schema.org",
      "@type": "FAQPage",
      "mainEntity": [
        {
          "@type": "Question",
          "name": "Should I move all authz to ReBAC?",
          "acceptedAnswer": {
            "@type": "Answer",
            "text": "Not necessarily. ReBAC shines for resource-graph problems (sharing, hierarchies, multi-tenancy). Coarse role checks are fine in RBAC. Most mature systems use ReBAC for resource permissions and RBAC for org-wide roles."
          }
        }
      ]
    }
  ]
---

[![IDSync — identity software buyer platform](/assets/idsync-logo-BKS89EW4.png)](/)

[Directory](/directory)

[Compare](/compare)

[Resources](/resources)

[Browse tools](/directory)[Run Stack Finder](/stack-finder)

1.  [Home](/)
2.  [Glossary](/glossary)
3.  Relationship-Based Access Control 

Authorization

# Relationship-Based Access Control (ReBAC)

ReBAC models authorization as a graph of relationships — \*user is editor of document, document is in folder, folder belongs to team\* — making it ideal for collaborative products like Google Docs, Notion, GitHub, and Figma.

Last reviewed 3 months ago

Key points

-   Popularized by Google's Zanzibar paper (2019)
-   Native fit for collaboration, sharing, and hierarchical resources
-   Decision = graph traversal over user-resource relationships
-   Open-source implementations: SpiceDB, OpenFGA, Ory Keto, Warrant
-   Coexists with RBAC and ABAC — not always a replacement

## What it is

Relationship-Based Access Control (ReBAC) describes authorization in terms of _relationships_ between subjects and resources, not just roles or attributes. _Alice is an editor of doc:123. Doc:123 is in folder:42. Folder:42 is owned by team:design._ Whether Alice can edit doc:123 is a graph traversal.

ReBAC was popularized by Google's 2019 **Zanzibar** paper describing the system that powers sharing in Google Docs, Drive, Calendar, and YouTube.

## How it works

You model a schema of object types and relations (`document { editor, viewer, parent: folder }`). You write relationship tuples (`document:123#editor@user:alice`). At check time the engine answers `check(user:alice, edit, document:123)` by walking the relationship graph.

## When buyers care

-   Building B2B SaaS with sharing, collaboration, or multi-tenant hierarchies
-   Replacing tangled application-level permission code
-   Anyone whose current authorization is a bug factory of `if user.role == ... and resource.team_id == ...`
-   Centralizing authz across many services (the Zanzibar pattern)

## ReBAC vs RBAC vs ABAC

-   **RBAC** — _which role do you have?_
-   **ABAC** — _what attributes do you, the resource, and the environment have?_
-   **ReBAC** — _what is your relationship to this specific resource?_

Real apps usually combine all three.

## Tools

-   **SpiceDB** (Authzed) — open-source Zanzibar implementation, hosted offering available
-   **OpenFGA** (Okta/Auth0) — CNCF Sandbox project
-   **Permit.io, Warrant, Cerbos** — broader authorization platforms with ReBAC support
-   **Ory Keto** — open-source Zanzibar-inspired engine

## FAQ

### Should I move all authz to ReBAC?

Not necessarily. ReBAC shines for resource-graph problems (sharing, hierarchies, multi-tenancy). Coarse role checks are fine in RBAC. Most mature systems use ReBAC for resource permissions and RBAC for org-wide roles.

IDSync provides educational buyer guidance based on publicly available information, editorial review, and user-submitted data. Vendor information should be verified before purchase. [Who we are, our methodology & disclosure policy](/about).

### One identity concept, explained per issue

Get vendor-neutral identity explainers and market updates in your inbox.

Work email\* 

Name

Company

Role (optional)

Interests (optional)

Pick what you want more of.

IAMCIAMSSO/MFAIGA/PAMSCIM/provisioningAI agent identityVendor updatesSecurity incidents

Subscribe

Twice-monthly identity digest. Curated, vendor-neutral. Unsubscribe any time.

### Vendor categories

[authorization](/directory/category/authorization)

### Vendors to evaluate

[auth0](/directory/auth0)[cerbos](/directory/cerbos)[permit io](/directory/permit-io)

### Not sure which tool you need?

Run the IAM Stack Finder for a vendor-neutral shortlist tailored to your stack.

[Run the Stack Finder](/stack-finder)

### Explore tools for this topic

Browse vetted vendors in the authorization category.

[Explore tools](/directory/category/authorization)

[![IDSync home](/assets/idsync-logo-BKS89EW4.png)](/)

The buyer-focused platform for identity, access, and authentication software.

#### Platform

-   [Home](/)
-   [IAM Stack Finder](/stack-finder)
-   [Directory](/directory)
-   [Resources](/resources)
-   [State of AI Agent Identity 2026](/reports/state-of-ai-agent-identity-2026)
-   [Buyer Guides](/guides)
-   [Glossary](/glossary)
-   [Newsletter](/newsletter)
-   [Newsletter Archive](/newsletter/archive)

#### Best of guides

-   [All comparisons](/compare)
-   [All vendor alternatives](/alternatives)
-   [Best SSO tools](/compare/best-sso-tools)
-   [Best MFA tools](/compare/best-mfa-tools)
-   [Best PAM tools](/compare/best-pam-tools)
-   [Best IGA tools](/compare/best-iga-tools)
-   [Best CIAM tools](/compare/best-ciam-tools)
-   [Best passwordless auth](/compare/best-passwordless-authentication-tools)
-   [Best identity security](/compare/best-identity-security-tools)
-   [Best machine identity](/compare/best-machine-identity-tools)
-   [Best SaaS access governance](/compare/best-saas-access-governance-tools)
-   [Best developer auth](/compare/best-developer-authentication-tools)
-   [Best for startups](/compare/best-iam-tools-for-startups)
-   [Best for enterprises](/compare/best-iam-tools-for-enterprises)
-   [Best SCIM tools](/compare/best-scim-provisioning-tools)
-   [Best for AI agents](/compare/best-ai-agent-identity-tools)
-   [Best NHI tools](/compare/best-nhi-management-tools)
-   [Okta pricing explained](/guides/okta-pricing)
-   [Auth0 pricing explained](/guides/auth0-pricing)
-   [Okta alternatives](/alternatives/okta)
-   [Auth0 alternatives](/alternatives/auth0)

#### For Vendors

-   [Sponsor](/sponsor)
-   [Badges](/badges)
-   [Submit Product](/submit-product)
-   [Claim Profile](/claim-profile)
-   [Partner](/partner)

#### Company

-   [About & Methodology](/about)
-   [Contact](/contact)
-   [Privacy](/privacy)

Vendor names, logos, and trademarks are the property of their respective owners. IDSync is an independent buyer resource and does not imply endorsement unless explicitly stated. Logos are displayed for identification purposes only.

IDSync (idsync.com) is operated by TetraCore, Bowling Green, Ohio. It is not affiliated with the IDSync® Active Directory synchronizer by Identity Syncronizer — [learn more](/about#idsync-disambiguation).

© 2026 IDSync. All rights reserved.

Editorial independence. Sponsored placements are clearly disclosed.