Skip to main content
Role-based access control

Role-based access control

Search complete. 48 mentions across 36 episodes found for "Role-based access control".

Sep 10, 2026

Paul AsadoorianHOST
41:06
But I think this also translates to, again, Jeff, back to your back to basics thing.
Paul AsadoorianHOST
41:15
If you're doing RBAC and access controls effectively and doing that well, when you have agents that are acting on behalf of your users, your other controls should help.
Paul AsadoorianHOST
41:32
Maybe not a hundred percent, which is maybe why you need some other kind of monitoring and visibility, but your access controls and permissions should be tuned accordingly so that when, for example, I as Paul Sidorium, use some frontier AI model that has connectors, which are agents, and I connect it to a number of different services, it rides on the back of, in this case, my credentials, right? I authorized my AI agent to use Atlassian JIRA, GitLab, Google Drive, What's the other popular one I use? Yeah, so even just those three, right? But I'm more confident that bad things will not happen because I can only, for example, manage my own repositories.
Paul AsadoorianHOST
42:24
In fact, I can't even delete anything.
Paul AsadoorianHOST
41:06
But I think this also translates to, again, Jeff, back to your back to basics thing.
Paul AsadoorianHOST
41:15
If you're doing RBAC and access controls effectively and doing that well, when you have agents that are acting on behalf of your users, your other controls should help.
Paul AsadoorianHOST
41:32
Maybe not 100%, which is maybe why you need some other kind of monitoring and visibility, but your access controls and permissions should be tuned correctly.
Paul AsadoorianHOST
41:42
accordingly so that when, for example, I, as Paul Sidorium, use some frontier AI model that has connectors, which are agents, and I connect it to a number of different services, it rides on the back of, in this case, my credentials, right? I authorized my AI agent to use Atlassian JIRA, GitLab, Google Drive, What's the other popular one I use? Yeah, so even just those three, right? But I'm more confident that bad things will not happen because I can only, for example, manage my own repositories.
Paul AsadoorianHOST
41:06
But I think this also translates to, again, Jeff, back to your back to basics thing.
Paul AsadoorianHOST
41:15
If you're doing RBAC and access controls effectively and doing that well, when you have agents that are acting on behalf of your users, your other controls should help.
Paul AsadoorianHOST
41:32
Maybe not a hundred percent, which is maybe why you need some other kind of monitoring and visibility, but your access controls and permissions should be tuned accordingly so that when, for example, I as Paul Sidorium, use some frontier AI model that has connectors, which are agents, and I connect it to a number of different services, it rides on the back of, in this case, my credentials, right? I authorized my AI agent to use Atlassian JIRA, GitLab, Google Drive, What's the other popular one I use? Yeah, so even just those three, right? But I'm more confident that bad things will not happen because I can only, for example, manage my own repositories.
Paul AsadoorianHOST
42:24
In fact, I can't even delete anything.
Paul AsadoorianHOST
41:06
But I think this also translates to, again, Jeff, back to your back to basics thing.
Paul AsadoorianHOST
41:15
If you're doing RBAC and access controls effectively and doing that well, when you have agents that are acting on behalf of your users, your other controls should help.
Paul AsadoorianHOST
41:32
Maybe not 100%, which is maybe why you need some other kind of monitoring and visibility, but your access controls and permissions should be tuned correctly.
Paul AsadoorianHOST
41:42
accordingly so that when, for example, I, as Paul Sidorium, use some frontier AI model that has connectors, which are agents, and I connect it to a number of different services, it rides on the back of, in this case, my credentials, right? I authorized my AI agent to use Atlassian JIRA, GitLab, Google Drive, What's the other popular one I use? Yeah, so even just those three, right? But I'm more confident that bad things will not happen because I can only, for example, manage my own repositories.
Sean GerberHOST
27:10
Lattice-based access controls.
Sean GerberHOST
27:11
So this is LBAC, not like RBAC or any of those other ones, LBAC.
Sean GerberHOST
27:17
This assigns subjects and objects a label in a lattice structure, such as top secret, secret, and confidential.
Sean GerberHOST
27:24
This is where you're dealing with mandatory access controls, and this really helps explain multi-level security and clearance levels.
Chaitanya KuberGUEST
50:01
It helps us secure data.
Chaitanya KuberGUEST
50:04
It's the RBAC.
Chaitanya KuberGUEST
50:05
Yeah, exactly.
Chaitanya KuberGUEST
50:06
It's the RBAC.
Chaitanya KuberGUEST
50:06
But that method helps us secure data in a way that doesn't limit access, doesn't create hurdles, and lets people explore.
Erin EvansHOST
50:14
Yeah.
Amir OfekGUEST
15:15
So even mover for humans is not working in my mind anywhere.
Amir OfekGUEST
15:20
That's exposing the lie of RBAC.
Amir OfekGUEST
15:22
It's not going to be applied.
Amir OfekGUEST
15:24
Exactly.
SeanHOST
4:33
I guess that's what I'm trying to figure out.
SeanHOST
4:35
How opinionated do I need to be? Do I need to solve some of these problems for these users, or do I let them solve it on their own? And one of the great examples of this is RBAC.
SeanHOST
4:45
You're coming to me.
SeanHOST
4:46
I'm handling all the authentication.
SeanHOST
4:33
I guess that's what I'm trying to figure out.
SeanHOST
4:35
How opinionated do I need to be? Do I need to solve some of these problems for these users, or do I let them solve it on their own? And one of the great examples of this is RBAC.
SeanHOST
4:45
You're coming to me.
SeanHOST
4:46
I'm handling all the authentication.
Chris SteffenHOST
5:57
It's still basically the Bible that's taught today.
Chris SteffenHOST
6:01
You move on to the 90s, you ended up with role-based access control.
Chris SteffenHOST
6:07
NIST finally, which is the standards body of the government, basically formalized role-based access control as the practical and scalable alternative to the messy and largely non-classified enterprise world.
Chris SteffenHOST
6:19
It tied it to a job role, not specifically to an individual person.
Chris SteffenHOST
6:24
So this is the first time where you saw a policy that Think of it very simply as the difference between an admin and a user.

26 more episodes mention Role-based access control.

Create an account to see the whole feed, search across every transcript, and follow the entities you care about.

We value your privacy

We use cookies to understand how you use our platform and to improve your experience. Click “Accept All” to consent, or “Decline non-essential” to opt out of non-essential cookies. Read our Privacy Policy.