What problem does it solve?
It prevents authorization design flaws that lead to privilege creep, role explosion, and weak separation of duties by guiding RBAC/ABAC decisions using NIST RBAC and NIST SP 800-162 as the evaluation backbone.
Core Features & Use Cases
- Framework-grounded authorization architecture guidance: Produces RBAC model-level and ABAC policy structure recommendations mapped to NIST references.
- Design-time assessment of RBAC maturity: Identifies common failure modes across RBAC model selection, hierarchy design, constraints (SoD/cardinality/prerequisites), and permission boundaries.
- ABAC patterning and role rationalization: Helps plan attribute-driven policies and role mining outcomes to reduce sprawl while preserving governance.
Quick Start
Use the rbac-design skill to design or refactor your role hierarchy and constraints for RBAC/ABAC authorization by reviewing the provided target-file-or-directory.