TL;DR: Role explosion, tenant-specific exceptions, and compliance evidence gaps push growing products beyond simple RBAC, according to Cerbos. Fine grained access control becomes essential once authorization must combine identity, resource, and context without scattering decisions across application code.
Editorial analysis by NHI Mgmt Group, based on content published by Cerbos: “Fine grained access control: What it actually takes to get it right”.
Key questions
Q: What breaks when role-based access control depends on too many exceptions?
A: The model stops being role-based in practice and becomes ticket-based.
Q: Why do fine grained policies make compliance evidence easier to produce?
A: They make evidence easier because each decision can capture the principal, action, resource, and context that justified access.
Q: What do teams get wrong when they hard-code authorization logic into each application?
A: The common mistake is treating authorization as app-specific plumbing instead of a shared control plane.
Practitioner guidance
- Audit role explosion patterns Map every role that exists only to satisfy one tenant, one department, or one exception.
- Externalize authorization decisions Move checks out of application code and into a dedicated decision layer so policy changes do not require repeated redeployments.
- Model the attributes your policies need Inventory principal, resource, and context attributes before you design the policy set.
Bottom line: Coarse roles work early, but they fail once access has to reflect tenant context, ownership, and business conditions.
Explore further
View Full Forum → | NHI Foundation Course → | Our Services → | Read the full analysis →
Role sprawl is usually a policy-design failure, not a staffing problem: Teams do not create too many roles because they lack discipline alone. They create too many roles because the underlying model cannot express the real access conditions the product now needs. The more tenant-specific exceptions and resource-level rules accumulate, the more role names become a surrogate for policy logic. The practitioner conclusion is to stop treating roles as the primary place to encode business nuance.
A question worth separating out:
Q: How should organisations govern non-human identities across their environment?
A: Start by inventorying every machine identity, assigning a human owner, and tying each one to a business purpose. Then apply routine access review, least privilege, and revocation for stale accounts. NHIs should be governed as accountable identities, not as background infrastructure that can be left unmanaged.
👉 Read our full editorial: Fine grained access control is the answer to role sprawl