Role-based access control, or RBAC, means permissions belong to roles, and users belong to roles. RBAC was formally articulated in 1992 by David Ferraiolo and Rick Kuhn, and NIST later formalized it in 2000 and standardized it as ANSI INCITS 359-2004 in 2004, with an updated ANSI INCITS