Skip to main content

← Back to glossary

Term · 9. Business Processes & Methodology

Role Explosion

IDM/IGA Domain
AuthZ Personal Data Introduced by: Gartner Introduced by: KuppingerCole

Definition

Pathology of RBAC implementations where role count grows uncontrollably — each exception or special case spawns a new role. Symptoms: thousands of roles with few members each, near-duplicate roles, role names indecipherable to business users. Defeats the management-simplification benefit of RBAC.

Application
MidPoint: Unreasonable multiplication of the number of roles in role-based access control (RBAC) systems.
Standards & regulations
  • NIST SP 800-162 «roles that are ad hoc and limited in membership, leading to what is often termed “role explosion”.»
Sources