Crash course: RBAC In Business
🔐 Building Amasoft’s Role-Based Access Control System in TypeDB 🔐
From Analyst to Architect - A professional learning journey
📋 Prologue: The Mandate
The IT Director has handed you a single-page brief. Amasoft - a mid-sized technology company that has grown through three acquisitions - has no centralised access control. Permissions live in spreadsheets. Role assignments are inconsistent across regions. Nobody has a clear picture of who has access to what, or why.
The compliance team has flagged it. The security team has flagged it. The auditors have flagged it. Your mandate: build Amasoft’s first centralised role-based access control (RBAC) system. Every identity, every system, every access grant, every policy - all of it in TypeDB.
Despite being intended as a learning journey for TypeDB, this is not just a toy project! The schema you build in this guide is a foundation you can adapt for your own company’s production-grade RBAC system. The queries you write are the queries a production RBAC system runs thousands of times a day. By the end, you will have:
-
Modelled a complete identity hierarchy - employees, contractors, interns, and service accounts
-
Built an org structure with reporting lines and department membership
-
Designed an access model that captures who has access, why, how, and until when
-
Written compliance-grade audit queries that answer the hard questions
-
Encoded access policies as reusable, composable TypeQL functions
-
Built a production-grade provisioning pipeline with idempotent inserts
|
👥 Cast of characters
|
|
🗺️ How to use this guide
Each chapter introduces new concepts through Amasoft’s story. Read the story, then study the code. Every code block is real TypeQL you can run in TypeDB Studio. At the end of each chapter you’ll find a Challenge to test your new skills. If you haven’t used the Chronicles of TypeDB, don’t worry - this guide is fully self-contained. If you have, you’ll recognise the patterns and find the concepts run deeper here in a real-world context. |